Weaknesses of type CWE-434

3,097 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-2219MEDIUMLoveCards LoveCardsV2 image unrestricted uploadEPSS 0.7%CVE-2023-45188MEDIUMIBM Engineering Lifecycle Optimization Publishing file uploadEPSS 0.7%CVE-2024-32514CRITICALWordPress WP Poll Maker plugin <= 3.4 - Authenticated Arbitrary File Upload vulnerabilityEPSS 0.7%CVE-2026-71805CRITICALAn arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary fEPSS 0.7%CVE-2025-23918CRITICALWordPress Smallerik File Browser plugin <= 1.1 - Arbitrary File Upload vulnerabilityEPSS 0.7%CVE-2023-32225CRITICAL Sysaid - CWE-434: Unrestricted Upload of File with Dangerous TypeEPSS 0.6%CVE-2025-2494HIGHUnrestricted file upload vulnerability in Softdial Contact CenterEPSS 0.6%CVE-2026-73373HIGHJoomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.6%CVE-2024-9985CRITICALRagic Enterprise Cloud Database - Arbitrary File UploadEPSS 0.6%CVE-2024-8746HIGHFile Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and UploadEPSS 0.6%CVE-2024-41339HIGHAn issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.EPSS 0.6%CVE-2026-1222HIGHBROWAN COMMUNICATIONS |PrismX MX100 AP controller - Arbitrary File UploadEPSS 0.6%CVE-2023-34207CRITICALUnrestricted Upload of File with Dangerous Type in EasyUse MailHunter UltimateEPSS 0.6%CVE-2023-41357HIGHGalaxy Software Services Vitals ESP - Arbitrary File UploadEPSS 0.6%CVE-2023-31215CRITICALWordPress Dropshipping & Affiliation with Amazon Plugin <= 2.1.2 is vulnerable to Arbitrary File UploadEPSS 0.6%CVE-2024-29100CRITICALWordPress AI Engine plugin <= 2.1.4 - Arbitrary File Upload vulnerabilityEPSS 0.6%CVE-2023-3800LOWEasyAdmin8 File Upload Module index.html unrestricted uploadEPSS 0.6%CVE-2023-22890HIGHSmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, caEPSS 0.6%CVE-2025-12399HIGHAlex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File UploadEPSS 0.6%CVE-2025-13069HIGHEnable SVG, WebP, and ICO Upload <= 1.1.3 - Authenticated (Author+) Arbitrary File Upload via ICO Upload BypassEPSS 0.6%