CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,381
Total CVEs
690
Critical
576
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 18
2 Ivanti 12
3 Zohocorp 12
4 Phpgurukul 7
5 Oretnom23 7
6 Mingsoft 7
7 Dedecms 7
8 Netgear 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,381)

CVE-2026-28289
10.0

This CVE describes a patch bypass vulnerability in FreeScout help desk software that allows authenticated users with file upload permissions to achiev...

Mar 3, 2026
CVE-2025-69828
10.0

A critical file upload vulnerability in TMS Global Software TMS Management Console allows remote attackers to upload malicious files through the Logo ...

Jan 22, 2026
CVE-2025-52691
KEV EPSS 82.7% 10.0

This critical vulnerability allows unauthenticated attackers to upload arbitrary files to any location on vulnerable SmarterMail servers, potentially ...

Dec 29, 2025
CVE-2025-67288
10.0

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to upload malicious PDF files that can lead to remote code execution. T...

Dec 22, 2025
CVE-2025-60207
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WooCommerce websites using the affected plugin. Attackers can ...

Nov 6, 2025
CVE-2025-60235
10.0

This vulnerability allows attackers to upload malicious files to WooCommerce sites using the Helpdesk Support Ticket System plugin. Attackers can uplo...

Nov 6, 2025
CVE-2025-53283
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Drop Uploader for CF7...

Nov 6, 2025
CVE-2025-64095
EPSS 38.4% 10.0

This vulnerability allows unauthenticated attackers to upload and overwrite files in DNN CMS systems. It enables website defacement and can be combine...

Oct 28, 2025
CVE-2025-49060
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable Wastia WordPress theme. Attacke...

Oct 22, 2025
CVE-2025-48106
10.0

This vulnerability allows attackers to upload malicious files to websites using the Clanora WordPress theme, potentially leading to complete system co...

Oct 22, 2025
CVE-2025-60219
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running vulnerable versions of the WooCommerce Designe...

Sep 26, 2025
CVE-2025-9846
10.0

This critical vulnerability in Inka.Net allows attackers to upload malicious files and execute arbitrary commands on the server. It affects all Talent...

Sep 23, 2025
CVE-2025-49387
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to websites using the Drag and Drop File Upload for Elementor For...

Aug 28, 2025
CVE-2025-48148
10.0

This vulnerability allows attackers to upload malicious files to WordPress sites using the StoreKeeper for WooCommerce plugin. Any WordPress site with...

Aug 20, 2025
CVE-2025-29009
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WooCommerce websites using the Medical Prescription Attachment...

Jul 16, 2025
CVE-2025-49414
10.0

This vulnerability allows attackers to upload malicious files to WordPress sites running FW Gallery plugin. Attackers can upload dangerous file types ...

Jul 4, 2025
CVE-2025-49885
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress sites using the Drag and Drop Multip...

Jun 27, 2025
CVE-2025-49444
10.0

This vulnerability allows attackers to upload arbitrary files including web shells to WordPress sites using the vulnerable Reformer for Elementor plug...

Jun 17, 2025
CVE-2025-49071
10.0

This critical vulnerability in the NasaTheme Flozen WordPress theme allows attackers to upload arbitrary files, including web shells, to the web serve...

Jun 17, 2025
CVE-2025-32291
10.0

This vulnerability allows attackers to upload malicious files to WordPress sites running the SUMO Affiliates Pro plugin. Attackers can exploit this to...

Jun 9, 2025
CVE-2025-39380
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to the Hospital Management System web server. This affects all ve...

May 19, 2025
CVE-2025-31324
KEV EPSS 34.3% 10.0

CVE-2025-31324 is an unauthenticated remote code execution vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows attackers to u...

Apr 24, 2025
CVE-2025-26927
10.0

This critical vulnerability in the EPC AI Hub WordPress plugin allows attackers to upload arbitrary files, including web shells, to the web server. An...

Apr 15, 2025
CVE-2025-22654
10.0

This vulnerability allows attackers to upload malicious files to WordPress sites using the Simplified plugin. It affects all WordPress installations r...

Feb 18, 2025
CVE-2025-23953
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the Innovative Solutions user files WordPr...

Jan 22, 2025
CVE-2025-22504
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable 4ECPS Web Forms WordPress plugi...

Jan 9, 2025
CVE-2024-43243
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable JobBoard Job Listing ...

Jan 7, 2025
CVE-2024-56064
10.0

CVE-2024-56064 is an unauthenticated arbitrary file upload vulnerability in the WP SuperBackup WordPress plugin. Attackers can upload malicious files ...

Dec 31, 2024
CVE-2024-53822
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Pie Register Premium plugin. Attackers can ...

Dec 9, 2024
CVE-2024-54214
10.0

CVE-2024-54214 is an unauthenticated arbitrary file upload vulnerability in the WordPress Revy plugin. Attackers can upload malicious files (including...

Dec 6, 2024
CVE-2024-52476
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Fediverse Embeds plugin. Attacke...

Dec 2, 2024
CVE-2024-52490
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to Pathomation servers due to insufficient file type validation. ...

Nov 28, 2024
CVE-2024-52379
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the kineticPay for WooCommerce plugin. Attacke...

Nov 14, 2024
CVE-2024-52376
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Boat Rental Plugin. A...

Nov 14, 2024
CVE-2024-52374
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the DoThatTask plugin. Attackers can...

Nov 14, 2024
CVE-2024-52372
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Easy CSV Importer BETA plugin. A...

Nov 14, 2024
CVE-2024-51792
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable Audio Record WordPress plugin. ...

Nov 11, 2024
CVE-2024-51790
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the HB AUDIO GALLERY plugin. Attacke...

Nov 11, 2024
CVE-2024-51788
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Novel Design Store Directory plu...

Nov 11, 2024
CVE-2024-50531
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites running the RSVPMaker for Toastmasters plugin....

Nov 4, 2024
CVE-2024-50526
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Multi...

Nov 4, 2024
CVE-2024-50523
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the All Post Contact Form plugin. At...

Nov 4, 2024
CVE-2024-50510
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the AR For Woocommerce plugin. Attac...

Oct 30, 2024
CVE-2024-50420
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the vulnerable aDirectory WordPress plugin...

Oct 29, 2024
CVE-2024-50484
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Multi Purpose Mail Form plugin. ...

Oct 29, 2024
CVE-2024-50494
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Sudan Payment Gateway...

Oct 29, 2024
CVE-2024-50495
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Plugi...

Oct 28, 2024
CVE-2024-49610
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the vulnerable photokit WordPress plugin. ...

Oct 20, 2024
CVE-2024-49330
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the Nice Backgrounds...

Oct 20, 2024
CVE-2024-49327
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Woost...

Oct 20, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,381 CVEs classified as CWE-434, with 690 rated critical and 576 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free