CWE-284: Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

1,311
Total CVEs
216
Critical
558
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
124
2025
669
2024
305
2023
121
2022
36

Top Affected Vendors

1 Microsoft 84
2 Apple 79
3 Oracle 57
4 Intel 32
5 Cisco 22
6 Adobe 21
7 Dell 20
8 Fabian 17
9 Mattermost 12
10 Campcodes 11

All Improper Access Control CVEs (1,311)

CVE-2026-2226
4.7

This vulnerability in DouPHP allows attackers to upload arbitrary files without restrictions via the /admin/file.php ZIP file handler by manipulating ...

Feb 9, 2026
CVE-2026-2213
4.7

This vulnerability allows remote attackers to upload arbitrary files to the Online Music Site 1.0 web application via the /Administrator/PHP/AdminAddA...

Feb 9, 2026
CVE-2026-1742
4.7

This vulnerability allows remote attackers to upload arbitrary files to the EFM ipTIME A8004T router via the VPN service component. Attackers can expl...

Feb 2, 2026
CVE-2026-1424
4.7

CVE-2026-1424 is an unrestricted file upload vulnerability in PHPGurukul News Portal 1.0's Profile Pic Handler component. This allows remote attackers...

Jan 26, 2026
CVE-2026-1152
4.7

This vulnerability in technical-laohu mpay up to version 1.2.4 allows remote attackers to upload arbitrary files via the QR Code Image Handler compone...

Jan 19, 2026
CVE-2025-15495
4.7

This vulnerability in BiggiDroid Simple PHP CMS 1.0 allows attackers to upload arbitrary files via the /admin/editsite.php endpoint due to insufficien...

Jan 9, 2026
CVE-2026-0566
4.7

This vulnerability allows remote attackers to upload arbitrary files to the code-projects CMS 1.0 system via the image parameter in the /admin/edit_po...

Jan 2, 2026
CVE-2025-15360
4.7

This vulnerability allows remote attackers to upload arbitrary files to newbee-mall-plus 2.0.0 through the product information edit page. Attackers ca...

Dec 30, 2025
CVE-2025-15262
4.7

BiggiDroid Simple PHP CMS 1.0 has an unrestricted file upload vulnerability in the Site Logo Handler component. Attackers can upload malicious files v...

Dec 30, 2025
CVE-2025-15197
4.7

This vulnerability allows remote attackers to upload arbitrary files to the Content Management System and News-Buzz 1.0 through the /admin/editposts.p...

Dec 29, 2025
CVE-2025-15110
4.7

This vulnerability allows remote attackers to upload arbitrary files to the jackq XCMS backend through the ProductImageController. Affected systems ar...

Dec 27, 2025
CVE-2025-14642
4.7

CVE-2025-14642 is an unrestricted file upload vulnerability in Computer Laboratory System 1.0 that allows remote attackers to upload malicious files v...

Dec 14, 2025
CVE-2025-14641
4.7

CVE-2025-14641 is an unrestricted file upload vulnerability in Computer Laboratory System 1.0's admin/admin_pic.php file. Attackers can remotely uploa...

Dec 14, 2025
CVE-2025-14582
4.7

This vulnerability in campcodes Online Student Enrollment System 1.0 allows attackers to upload arbitrary files via the userphoto parameter in the adm...

Dec 12, 2025
CVE-2025-14219
4.7

Campcodes Retro Basketball Shoes Online Store 1.0 has an unrestricted file upload vulnerability in the admin/admin_running.php file. Attackers can rem...

Dec 8, 2025
CVE-2025-13574
4.7

This vulnerability allows remote attackers to upload arbitrary files to the Online Bidding System 1.0 administrator interface via the catimage paramet...

Nov 24, 2025
CVE-2025-13423
4.7

This vulnerability allows remote attackers to upload arbitrary files to Campcodes Retro Basketball Shoes Online Store 1.0 via the product_image parame...

Nov 20, 2025
CVE-2025-13411
4.7

This vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 allows attackers to upload arbitrary files to the server via the product_image...

Nov 19, 2025
CVE-2025-13275
4.7

This vulnerability allows remote attackers to upload arbitrary files to the Iqbolshoh php-business-website through the /admin/about.php endpoint. It a...

Nov 17, 2025
CVE-2025-13198
4.7

This vulnerability allows attackers to upload arbitrary files to DouPHP systems without proper restrictions. It affects all DouPHP installations up to...

Nov 15, 2025
CVE-2025-13185
4.7

This vulnerability allows remote attackers to upload arbitrary files to the Bdtask/CodeCanyon News365 system via the profile_image/banner_image parame...

Nov 14, 2025
CVE-2025-12331
4.7

Willow CMS up to version 1.4.0 contains an unrestricted file upload vulnerability in the /admin/images/add endpoint. This allows attackers to upload m...

Oct 27, 2025
CVE-2025-12291
4.7

This vulnerability allows attackers to upload arbitrary files without restrictions on the Add Product page of affected ecommerce systems. It affects a...

Oct 27, 2025
CVE-2025-12201
4.7

This vulnerability allows remote attackers to upload arbitrary files through the image parameter in the User Management Interface of ajayrandhawa User...

Oct 27, 2025
CVE-2025-11655
4.7

This vulnerability allows remote attackers to upload arbitrary SVG files without proper restrictions in Total.js Flow. It affects all deployments usin...

Oct 13, 2025
CVE-2025-11508
4.7

This vulnerability in code-projects Voting System 1.0 allows remote attackers to upload arbitrary files via the photo parameter in /admin/voters_add.p...

Oct 8, 2025
CVE-2025-11470
4.7

This vulnerability allows attackers to upload arbitrary files to the Hotel and Lodge Management System through the /manage_website.php endpoint. Attac...

Oct 8, 2025
CVE-2025-11103
4.7

This vulnerability allows remote attackers to upload arbitrary files to the Projectworlds Online Tours and Travels 1.0 system via the /admin/change-im...

Sep 28, 2025
CVE-2025-10081
4.7

This vulnerability in SourceCodester Pet Management System 1.0 allows remote attackers to upload arbitrary files via the website_image parameter in /a...

Sep 8, 2025
CVE-2025-53791
4.7

An improper access control vulnerability in Microsoft Edge allows attackers to bypass security features over a network. This affects users of Microsof...

Sep 5, 2025
CVE-2025-9296
4.7

Emlog Pro up to version 2.5.18 contains an unrestricted file upload vulnerability in the avatar update function. Attackers can remotely upload malicio...

Aug 21, 2025
CVE-2025-7477
4.7

This critical vulnerability in Simple Car Rental System 1.0 allows remote attackers to upload arbitrary files via the image parameter in /admin/add_ca...

Jul 12, 2025
CVE-2025-6873
4.7

This vulnerability allows remote attackers to upload arbitrary files to Simple Company Website 1.0 via the /classes/Users.php?f=save endpoint. Attacke...

Jun 29, 2025
CVE-2025-5130
4.7

This critical vulnerability in Tmall Demo allows remote attackers to upload arbitrary files without restrictions via the uploadProductImage function. ...

May 24, 2025
CVE-2025-5059
4.7

Campcodes Online Shopping Portal 1.0 contains a critical vulnerability in the admin/edit-subcategory.php file that allows unrestricted file upload via...

May 21, 2025
CVE-2025-4926
4.7

This vulnerability allows remote attackers to upload arbitrary files to the PHPGurukul Car Rental Project 1.0 system via the /admin/post-avehical.php ...

May 19, 2025
CVE-2025-20223
4.7

This vulnerability in Cisco Catalyst Center (formerly DNA Center) allows authenticated remote attackers to bypass access controls and read/modify data...

May 7, 2025
CVE-2025-4006
4.7

This critical vulnerability in BeyongCms 1.6.0 allows remote attackers to upload arbitrary files without restrictions via the Document Management Page...

Apr 28, 2025
CVE-2025-3123
4.7

This vulnerability in WonderCMS 3.5.0 allows remote attackers to upload arbitrary files through the theme/plugin installation function, potentially le...

Apr 2, 2025
CVE-2025-0582
4.7

This critical vulnerability in itsourcecode Farm Management System allows remote attackers to upload arbitrary files via the /add-pig.php endpoint's p...

Jan 20, 2025
CVE-2025-0399
4.7

This vulnerability allows remote attackers to upload arbitrary files without restrictions in StarSea99 starsea-mall version 1.0. Attackers can exploit...

Jan 12, 2025
CVE-2024-13210
4.7

This vulnerability allows remote attackers to upload arbitrary files to the donglight bookstore e-commerce system through the uploadPicture function. ...

Jan 9, 2025
CVE-2024-13201
4.7

This vulnerability allows remote attackers to upload arbitrary files without restrictions in the SpringBoot-Blog 1.0 application. Attackers can exploi...

Jan 9, 2025
CVE-2024-13138
4.7

This vulnerability allows remote attackers to upload arbitrary files without restrictions in wangl1989 mysiteforme 1.0. Attackers can exploit this to ...

Jan 5, 2025
CVE-2024-11211
4.7

A critical vulnerability in EyouCMS allows unrestricted file uploads via the Website Logo Handler component, enabling attackers to upload malicious fi...

Nov 14, 2024
CVE-2024-11000
4.7

This vulnerability allows authenticated attackers to upload arbitrary files to the Real Estate Management System's About Us page. Attackers can exploi...

Nov 8, 2024
CVE-2024-42794
4.7

Kashipara Music Management System v1.0 has an incorrect access control vulnerability in the /music/ajax.php endpoint that allows unauthorized users to...

Sep 16, 2024
CVE-2024-8071
4.7

This vulnerability allows users with edit access to the permissions section of the Mattermost system console to escalate their privileges to System Ad...

Aug 22, 2024
CVE-2024-41732
4.7

This vulnerability in SAP NetWeaver Application Server ABAP allows unauthenticated attackers to craft URLs that bypass allowlist controls. Attackers c...

Aug 13, 2024
CVE-2025-40939
4.6

A vulnerability in SIMATIC CN 4100 devices allows attackers with physical access to trigger a denial-of-service reboot via the USB port. This affects ...

Dec 9, 2025

About Improper Access Control (CWE-284)

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Our database tracks 1,311 CVEs classified as CWE-284, with 216 rated critical and 558 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.

External reference: View CWE-284 on MITRE CWE →

Monitor Improper Access Control Vulnerabilities

Get alerted when new Improper Access Control CVEs affect your infrastructure.

Start Monitoring Free