Weaknesses of type CWE-434

3,097 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2026-18983HIGHOne User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file ParameterEPSS 0.7%CVE-2025-9515HIGHMulti Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File UploadEPSS 0.7%CVE-2025-12528HIGHPie Forms for WP <= 1.6 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2023-27881HIGHPTC Vuforia Studio Unrestricted Upload of File with Dangerous TypeEPSS 0.7%CVE-2025-11889HIGHAIO Forms <= 1.3.18 - Authenticated (Admin+) Arbitrary File Upload via Zip ImportEPSS 0.7%CVE-2020-6288MEDIUMSAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to uploadEPSS 0.7%CVE-2024-25636HIGHLack of media type verification of Activity Streams objects allows impersonation and takeover of remote accountsEPSS 0.7%CVE-2026-2269HIGHUncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File UploadEPSS 0.7%CVE-2025-34163CRITICALDongsheng Logistics Software Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2024-24024CRITICALAn arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownEPSS 0.7%CVE-2024-24025CRITICALAn arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). EPSS 0.7%CVE-2026-33582MEDIUMApache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory errorEPSS 0.7%CVE-2019-25714CRITICALSeeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservletEPSS 0.7%CVE-2024-40394CRITICALSimple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the compoEPSS 0.7%CVE-2024-7329MEDIUMYouDianCMS image_upload.php unrestricted uploadEPSS 0.7%CVE-2025-22152CRITICALImproper Path Validation Enables Path Traversal in Multiple Components in AtheosEPSS 0.7%CVE-2023-31231CRITICALWordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin <= 1.5.65 is vulnerable to Arbitrary File UploadEPSS 0.7%CVE-2023-53950CRITICALInnovaStudio WYSIWYG Editor 5.4 Unrestricted File Upload via Filename ManipulationEPSS 0.7%CVE-2026-24727CRITICALSUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous TypeEPSS 0.7%CVE-2023-45188MEDIUMIBM Engineering Lifecycle Optimization Publishing file uploadEPSS 0.7%