Weaknesses of type CWE-434

3,099 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-11724HIGHEM Beer Manager <= 3.2.3 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.6%CVE-2025-8323HIGHVentem|e-School - Arbitrary File UploadEPSS 0.6%CVE-2025-11659MEDIUMProjectsAndPrograms School Management System uploadNotes.php unrestricted uploadEPSS 0.6%CVE-2025-11656MEDIUMProjectsAndPrograms School Management System editNotes.php unrestricted uploadEPSS 0.6%CVE-2025-11657MEDIUMProjectsAndPrograms School Management System createNotice.php unrestricted uploadEPSS 0.6%CVE-2023-51421CRITICALWordPress Verge3D Plugin <= 4.5.2 is vulnerable to Arbitrary File UploadEPSS 0.6%CVE-2024-3123HIGHCHANGING Mobile One Time Password - Arbitrary File UploadEPSS 0.6%CVE-2024-2059MEDIUMSourceCodester Petrol Pump Management Software service_crud.php unrestricted uploadEPSS 0.6%CVE-2026-57581MEDIUMDotVVM: Unrestricted file uploadEPSS 0.6%CVE-2025-29093HIGHFile Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/GaEPSS 0.6%CVE-2025-61506CRITICALAn issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /uplEPSS 0.6%CVE-2020-37009HIGHMedDream PACS Server 6.8.3.751 - Remote Code ExecutionEPSS 0.6%CVE-2024-1260MEDIUMJuanpao JPShop API ComboController.php actionIndex unrestricted uploadEPSS 0.6%CVE-2025-15226CRITICALSunnet|WMPro - Arbitrary File UploadEPSS 0.6%CVE-2024-1268MEDIUMCodeAstro Restaurant POS System update_product.php unrestricted uploadEPSS 0.6%CVE-2024-1263MEDIUMJuanpao JPShop API PosterController.php actionUpdate unrestricted uploadEPSS 0.6%CVE-2024-1264MEDIUMJuanpao JPShop UploadsController.php actionUpdate unrestricted uploadEPSS 0.6%CVE-2024-0468MEDIUMcode-projects Fighting Cock Information System new-father.php unrestricted uploadEPSS 0.6%CVE-2024-1262MEDIUMJuanpao JPShop API MaterialController.php actionUpdate unrestricted uploadEPSS 0.6%CVE-2026-52835HIGHTautulli: Path traversal / arbitrary file write via unsanitized upload filename in import_config and import_databaseEPSS 0.6%