CWE-284: Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Yearly Trend
Top Affected Vendors
All Improper Access Control CVEs (1,311)
This vulnerability in DouPHP allows attackers to upload arbitrary files without restrictions via the /admin/file.php ZIP file handler by manipulating ...
Feb 9, 2026This vulnerability allows remote attackers to upload arbitrary files to the Online Music Site 1.0 web application via the /Administrator/PHP/AdminAddA...
Feb 9, 2026This vulnerability allows remote attackers to upload arbitrary files to the EFM ipTIME A8004T router via the VPN service component. Attackers can expl...
Feb 2, 2026CVE-2026-1424 is an unrestricted file upload vulnerability in PHPGurukul News Portal 1.0's Profile Pic Handler component. This allows remote attackers...
Jan 26, 2026This vulnerability in technical-laohu mpay up to version 1.2.4 allows remote attackers to upload arbitrary files via the QR Code Image Handler compone...
Jan 19, 2026This vulnerability in BiggiDroid Simple PHP CMS 1.0 allows attackers to upload arbitrary files via the /admin/editsite.php endpoint due to insufficien...
Jan 9, 2026This vulnerability allows remote attackers to upload arbitrary files to the code-projects CMS 1.0 system via the image parameter in the /admin/edit_po...
Jan 2, 2026This vulnerability allows remote attackers to upload arbitrary files to newbee-mall-plus 2.0.0 through the product information edit page. Attackers ca...
Dec 30, 2025BiggiDroid Simple PHP CMS 1.0 has an unrestricted file upload vulnerability in the Site Logo Handler component. Attackers can upload malicious files v...
Dec 30, 2025This vulnerability allows remote attackers to upload arbitrary files to the Content Management System and News-Buzz 1.0 through the /admin/editposts.p...
Dec 29, 2025This vulnerability allows remote attackers to upload arbitrary files to the jackq XCMS backend through the ProductImageController. Affected systems ar...
Dec 27, 2025CVE-2025-14642 is an unrestricted file upload vulnerability in Computer Laboratory System 1.0 that allows remote attackers to upload malicious files v...
Dec 14, 2025CVE-2025-14641 is an unrestricted file upload vulnerability in Computer Laboratory System 1.0's admin/admin_pic.php file. Attackers can remotely uploa...
Dec 14, 2025This vulnerability in campcodes Online Student Enrollment System 1.0 allows attackers to upload arbitrary files via the userphoto parameter in the adm...
Dec 12, 2025Campcodes Retro Basketball Shoes Online Store 1.0 has an unrestricted file upload vulnerability in the admin/admin_running.php file. Attackers can rem...
Dec 8, 2025This vulnerability allows remote attackers to upload arbitrary files to the Online Bidding System 1.0 administrator interface via the catimage paramet...
Nov 24, 2025This vulnerability allows remote attackers to upload arbitrary files to Campcodes Retro Basketball Shoes Online Store 1.0 via the product_image parame...
Nov 20, 2025This vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 allows attackers to upload arbitrary files to the server via the product_image...
Nov 19, 2025This vulnerability allows remote attackers to upload arbitrary files to the Iqbolshoh php-business-website through the /admin/about.php endpoint. It a...
Nov 17, 2025This vulnerability allows attackers to upload arbitrary files to DouPHP systems without proper restrictions. It affects all DouPHP installations up to...
Nov 15, 2025This vulnerability allows remote attackers to upload arbitrary files to the Bdtask/CodeCanyon News365 system via the profile_image/banner_image parame...
Nov 14, 2025Willow CMS up to version 1.4.0 contains an unrestricted file upload vulnerability in the /admin/images/add endpoint. This allows attackers to upload m...
Oct 27, 2025This vulnerability allows attackers to upload arbitrary files without restrictions on the Add Product page of affected ecommerce systems. It affects a...
Oct 27, 2025This vulnerability allows remote attackers to upload arbitrary files through the image parameter in the User Management Interface of ajayrandhawa User...
Oct 27, 2025This vulnerability allows remote attackers to upload arbitrary SVG files without proper restrictions in Total.js Flow. It affects all deployments usin...
Oct 13, 2025This vulnerability in code-projects Voting System 1.0 allows remote attackers to upload arbitrary files via the photo parameter in /admin/voters_add.p...
Oct 8, 2025This vulnerability allows attackers to upload arbitrary files to the Hotel and Lodge Management System through the /manage_website.php endpoint. Attac...
Oct 8, 2025This vulnerability allows remote attackers to upload arbitrary files to the Projectworlds Online Tours and Travels 1.0 system via the /admin/change-im...
Sep 28, 2025This vulnerability in SourceCodester Pet Management System 1.0 allows remote attackers to upload arbitrary files via the website_image parameter in /a...
Sep 8, 2025An improper access control vulnerability in Microsoft Edge allows attackers to bypass security features over a network. This affects users of Microsof...
Sep 5, 2025Emlog Pro up to version 2.5.18 contains an unrestricted file upload vulnerability in the avatar update function. Attackers can remotely upload malicio...
Aug 21, 2025This critical vulnerability in Simple Car Rental System 1.0 allows remote attackers to upload arbitrary files via the image parameter in /admin/add_ca...
Jul 12, 2025This vulnerability allows remote attackers to upload arbitrary files to Simple Company Website 1.0 via the /classes/Users.php?f=save endpoint. Attacke...
Jun 29, 2025This critical vulnerability in Tmall Demo allows remote attackers to upload arbitrary files without restrictions via the uploadProductImage function. ...
May 24, 2025Campcodes Online Shopping Portal 1.0 contains a critical vulnerability in the admin/edit-subcategory.php file that allows unrestricted file upload via...
May 21, 2025This vulnerability allows remote attackers to upload arbitrary files to the PHPGurukul Car Rental Project 1.0 system via the /admin/post-avehical.php ...
May 19, 2025This vulnerability in Cisco Catalyst Center (formerly DNA Center) allows authenticated remote attackers to bypass access controls and read/modify data...
May 7, 2025This critical vulnerability in BeyongCms 1.6.0 allows remote attackers to upload arbitrary files without restrictions via the Document Management Page...
Apr 28, 2025This vulnerability in WonderCMS 3.5.0 allows remote attackers to upload arbitrary files through the theme/plugin installation function, potentially le...
Apr 2, 2025This critical vulnerability in itsourcecode Farm Management System allows remote attackers to upload arbitrary files via the /add-pig.php endpoint's p...
Jan 20, 2025This vulnerability allows remote attackers to upload arbitrary files without restrictions in StarSea99 starsea-mall version 1.0. Attackers can exploit...
Jan 12, 2025This vulnerability allows remote attackers to upload arbitrary files to the donglight bookstore e-commerce system through the uploadPicture function. ...
Jan 9, 2025This vulnerability allows remote attackers to upload arbitrary files without restrictions in the SpringBoot-Blog 1.0 application. Attackers can exploi...
Jan 9, 2025This vulnerability allows remote attackers to upload arbitrary files without restrictions in wangl1989 mysiteforme 1.0. Attackers can exploit this to ...
Jan 5, 2025A critical vulnerability in EyouCMS allows unrestricted file uploads via the Website Logo Handler component, enabling attackers to upload malicious fi...
Nov 14, 2024This vulnerability allows authenticated attackers to upload arbitrary files to the Real Estate Management System's About Us page. Attackers can exploi...
Nov 8, 2024Kashipara Music Management System v1.0 has an incorrect access control vulnerability in the /music/ajax.php endpoint that allows unauthorized users to...
Sep 16, 2024This vulnerability allows users with edit access to the permissions section of the Mattermost system console to escalate their privileges to System Ad...
Aug 22, 2024This vulnerability in SAP NetWeaver Application Server ABAP allows unauthenticated attackers to craft URLs that bypass allowlist controls. Attackers c...
Aug 13, 2024A vulnerability in SIMATIC CN 4100 devices allows attackers with physical access to trigger a denial-of-service reboot via the USB port. This affects ...
Dec 9, 2025About Improper Access Control (CWE-284)
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Our database tracks 1,311 CVEs classified as CWE-284, with 216 rated critical and 558 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.
External reference: View CWE-284 on MITRE CWE →
Monitor Improper Access Control Vulnerabilities
Get alerted when new Improper Access Control CVEs affect your infrastructure.
Start Monitoring Free