CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,390)
This CVE describes a patch bypass vulnerability in FreeScout help desk software that allows authenticated users with file upload permissions to achiev...
Mar 3, 2026A critical file upload vulnerability in TMS Global Software TMS Management Console allows remote attackers to upload malicious files through the Logo ...
Jan 22, 2026This critical vulnerability allows unauthenticated attackers to upload arbitrary files to any location on vulnerable SmarterMail servers, potentially ...
Dec 29, 2025An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to upload malicious PDF files that can lead to remote code execution. T...
Dec 22, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WooCommerce websites using the affected plugin. Attackers can ...
Nov 6, 2025This vulnerability allows attackers to upload malicious files to WooCommerce sites using the Helpdesk Support Ticket System plugin. Attackers can uplo...
Nov 6, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Drop Uploader for CF7...
Nov 6, 2025This vulnerability allows unauthenticated attackers to upload and overwrite files in DNN CMS systems. It enables website defacement and can be combine...
Oct 28, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable Wastia WordPress theme. Attacke...
Oct 22, 2025This vulnerability allows attackers to upload malicious files to websites using the Clanora WordPress theme, potentially leading to complete system co...
Oct 22, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running vulnerable versions of the WooCommerce Designe...
Sep 26, 2025This critical vulnerability in Inka.Net allows attackers to upload malicious files and execute arbitrary commands on the server. It affects all Talent...
Sep 23, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to websites using the Drag and Drop File Upload for Elementor For...
Aug 28, 2025This vulnerability allows attackers to upload malicious files to WordPress sites using the StoreKeeper for WooCommerce plugin. Any WordPress site with...
Aug 20, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WooCommerce websites using the Medical Prescription Attachment...
Jul 16, 2025This vulnerability allows attackers to upload malicious files to WordPress sites running FW Gallery plugin. Attackers can upload dangerous file types ...
Jul 4, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress sites using the Drag and Drop Multip...
Jun 27, 2025This vulnerability allows attackers to upload arbitrary files including web shells to WordPress sites using the vulnerable Reformer for Elementor plug...
Jun 17, 2025This critical vulnerability in the NasaTheme Flozen WordPress theme allows attackers to upload arbitrary files, including web shells, to the web serve...
Jun 17, 2025This vulnerability allows attackers to upload malicious files to WordPress sites running the SUMO Affiliates Pro plugin. Attackers can exploit this to...
Jun 9, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to the Hospital Management System web server. This affects all ve...
May 19, 2025CVE-2025-31324 is an unauthenticated remote code execution vulnerability in SAP NetWeaver Visual Composer Metadata Uploader that allows attackers to u...
Apr 24, 2025This critical vulnerability in the EPC AI Hub WordPress plugin allows attackers to upload arbitrary files, including web shells, to the web server. An...
Apr 15, 2025This vulnerability allows attackers to upload malicious files to WordPress sites using the Simplified plugin. It affects all WordPress installations r...
Feb 18, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the Innovative Solutions user files WordPr...
Jan 22, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable 4ECPS Web Forms WordPress plugi...
Jan 9, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable JobBoard Job Listing ...
Jan 7, 2025CVE-2024-56064 is an unauthenticated arbitrary file upload vulnerability in the WP SuperBackup WordPress plugin. Attackers can upload malicious files ...
Dec 31, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Pie Register Premium plugin. Attackers can ...
Dec 9, 2024CVE-2024-54214 is an unauthenticated arbitrary file upload vulnerability in the WordPress Revy plugin. Attackers can upload malicious files (including...
Dec 6, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Fediverse Embeds plugin. Attacke...
Dec 2, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to Pathomation servers due to insufficient file type validation. ...
Nov 28, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the kineticPay for WooCommerce plugin. Attacke...
Nov 14, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Boat Rental Plugin. A...
Nov 14, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the DoThatTask plugin. Attackers can...
Nov 14, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Easy CSV Importer BETA plugin. A...
Nov 14, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable Audio Record WordPress plugin. ...
Nov 11, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the HB AUDIO GALLERY plugin. Attacke...
Nov 11, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Novel Design Store Directory plu...
Nov 11, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites running the RSVPMaker for Toastmasters plugin....
Nov 4, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Multi...
Nov 4, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the All Post Contact Form plugin. At...
Nov 4, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the AR For Woocommerce plugin. Attac...
Oct 30, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the vulnerable aDirectory WordPress plugin...
Oct 29, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Multi Purpose Mail Form plugin. ...
Oct 29, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Sudan Payment Gateway...
Oct 29, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Plugi...
Oct 28, 2024This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the vulnerable photokit WordPress plugin. ...
Oct 20, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the Nice Backgrounds...
Oct 20, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Woost...
Oct 20, 2024About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,390 CVEs classified as CWE-434, with 694 rated critical and 581 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free