Skip to content
Noroxi

CWE-616 · 7 records

Incomplete Identification of Uploaded File Variables (PHP)

CVEs in this class

7 records

  • File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which

    CriticalCVSS 9.9No exploitEPSS 0%

    invoiceplane · invoiceplaneJan 15, 2026

  • In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

    CriticalCVSS 9.8No exploitEPSS 0%

    misp-project · mispMar 21, 2024

  • An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.

    CriticalCVSS 9.8No exploitEPSS 0%

    Apr 26, 2024

  • Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher

    HighCVSS 8.7No exploitEPSS 0%

    perspective-dev · perspectiveAug 4, 2026

  • Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL

    MediumCVSS 5.4No exploitEPSS 0%

    flocksafety · bravo compute box firmwareSep 25, 2025

  • File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller.

    MediumCVSS 5.4No exploitEPSS 0%

    Aug 25, 2025

  • UnoPim Stored XSS : Cookie hijacking through Create User function

    MediumCVSS 4.8No exploitEPSS 0%

    webkul · unopimNov 13, 2024

All vulnerability classes