CWE-616 · 7 records
Incomplete Identification of Uploaded File Variables (PHP)
CVEs in this class
7 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-67084No exploit | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, whichinvoiceplane · invoiceplane · CWE-616 | Critical9.9 | — | 0.5% | Jan 15, 2026 |
39Monitor | CVE-2024-29858No exploit | In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.misp-project · misp · CWE-616 | Critical9.8 | — | 0.4% | Mar 21, 2024 |
39Monitor | CVE-2024-31601No exploit | An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.CWE-616 | Critical9.8 | — | 0.4% | Apr 26, 2024 |
34Monitor | CVE-2026-67198No exploit | Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcherperspective-dev · perspective · CWE-616 | High8.7 | — | 0.3% | Aug 4, 2026 |
21Monitor | CVE-2025-59402No exploit | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL flocksafety · bravo compute box firmware · CWE-616 | Medium5.4 | — | 0.2% | Sep 25, 2025 |
21Monitor | CVE-2025-52130No exploit | File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller.CWE-616 | Medium5.4 | — | 0.2% | Aug 25, 2025 |
19Monitor | CVE-2024-52305No exploit | UnoPim Stored XSS : Cookie hijacking through Create User functionwebkul · unopim · CWE-616 | Medium4.8 | — | 0.2% | Nov 13, 2024 |
- CVE-2025-6708439Monitor
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which
CriticalCVSS 9.9No exploitEPSS 0%invoiceplane · invoiceplaneJan 15, 2026
- CVE-2024-2985839Monitor
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
CriticalCVSS 9.8No exploitEPSS 0%misp-project · mispMar 21, 2024
- CVE-2024-3160139Monitor
An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.
CriticalCVSS 9.8No exploitEPSS 0%Apr 26, 2024
- CVE-2026-6719834Monitor
Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher
HighCVSS 8.7No exploitEPSS 0%perspective-dev · perspectiveAug 4, 2026
- CVE-2025-5940221Monitor
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL
MediumCVSS 5.4No exploitEPSS 0%flocksafety · bravo compute box firmwareSep 25, 2025
- CVE-2025-5213021Monitor
File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller.
MediumCVSS 5.4No exploitEPSS 0%Aug 25, 2025
- CVE-2024-5230519Monitor
UnoPim Stored XSS : Cookie hijacking through Create User function
MediumCVSS 4.8No exploitEPSS 0%webkul · unopimNov 13, 2024