CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,408)
CVE-2022-48079 is a critical privilege escalation vulnerability in Monnai aaPanel host system v1.5 that allows attackers to upload malicious PHP files...
Feb 2, 2023CVE-2022-47769 is an arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 that allows unauthenticated attackers to upload m...
Feb 1, 2023This vulnerability allows unauthenticated attackers to upload arbitrary files to the Hiby R3 PRO device via its web server interface. This affects all...
Jul 29, 2022DataEase v1.11.1 contains an arbitrary file write vulnerability via the dataSourceId parameter. This allows attackers to write arbitrary files to the ...
Jul 22, 2022CVE-2021-36711 is a critical remote code execution vulnerability in OctoBot's WebInterface that allows attackers to upload malicious Tentacles (plugin...
Jul 16, 2022This vulnerability allows remote attackers on the local network to execute arbitrary code as root on Verizon 5G Home LVSKIHP InDoorUnit devices. The d...
Jul 14, 2022This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the Free Booking Plugin for Hotels, Restauran...
Jul 11, 2022This vulnerability allows unauthenticated attackers to upload arbitrary files to GFI Mail Archiver servers via insecure Telerik Web UI components. It ...
Jul 7, 2022Halo CMS v1.5.3 contains an arbitrary file upload vulnerability in the /api/admin/attachments/upload endpoint that allows authenticated attackers to u...
Jun 27, 2022CVE-2021-38945 is a critical vulnerability in IBM Cognos Analytics that allows remote attackers to upload arbitrary files due to improper content vali...
Jun 24, 2022Laiketui 3.5.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the server. This can lead to remote ...
Jun 23, 2022Monstra CMS 3.0.4 has an unrestricted file upload vulnerability due to insufficient filtering of PHP file extensions. Attackers can upload malicious P...
Jun 15, 2022Car Rental Management System v1.0 contains an unrestricted file upload vulnerability in the admin/ajax.php endpoint that allows remote attackers to ex...
Jun 2, 2022EliteCMS 1.0.1 contains a critical vulnerability in the admin/manage_uploads.php file that allows authenticated attackers to upload malicious files an...
Jun 2, 2022CVE-2022-30506 is an arbitrary file upload vulnerability in MCMS 5.2.7 that allows attackers to upload malicious ZIP files containing executable code....
Jun 2, 2022ACEweb Online Portal 3.5.065 contains an unrestricted file upload vulnerability in the attachments.awp component. This allows attackers to upload mali...
Jun 2, 2022This vulnerability allows attackers to upload malicious files to the Roncoo Education platform's course API endpoint, which can lead to remote code ex...
May 26, 2022SiteServer CMS versions before 5.1 contain an unrestricted file upload vulnerability that allows attackers to upload malicious files and execute arbit...
May 24, 2022Pharmacy Management System v1.0 contains a critical remote code execution vulnerability in the /php_action/editProductImage.php component. Attackers c...
May 20, 2022Foxit PDF Editor v11.3.1 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the system. This affects a...
May 20, 2022CVE-2022-29351 is an arbitrary file upload vulnerability in TiddlyWiki5 v5.2.2 that allows attackers to upload malicious SVG files containing JavaScri...
May 16, 2022CVE-2022-29354 is an arbitrary file upload vulnerability in Keystone v4.2.1 that allows attackers to upload malicious files and execute arbitrary code...
May 16, 2022This vulnerability allows attackers to upload malicious JSP files without restrictions in novel-plus's file controller. It affects all versions of nov...
May 13, 2022CVE-2022-30448 is an unauthenticated file upload vulnerability in Hospital Management System (HMS) 1.0 that allows attackers to upload arbitrary files...
May 11, 2022This vulnerability allows attackers to upload malicious files to the Open Virtual Simulation Experiment Teaching Management Platform software version ...
May 5, 2022CVE-2022-28568 is a critical vulnerability in Sourcecodester Doctor's Appointment System 1.0 that allows authenticated administrators to upload malici...
May 4, 2022CVE-2022-29347 is an arbitrary file upload vulnerability in Web@rchiv 1.0 that allows attackers to upload malicious PHP files. This enables remote cod...
May 4, 2022CVE-2021-41921 is an unrestricted file upload vulnerability in novel-plus V3.6.1 that allows attackers to upload malicious files with arbitrary extens...
Apr 28, 2022CVE-2022-27468 is a critical arbitrary file upload vulnerability in Monstaftp v2.10.3 that allows attackers to upload malicious files to the web serve...
Apr 26, 2022CVE-2022-28021 is a remote code execution vulnerability in Purchase Order Management System v1.0, allowing attackers to execute arbitrary code via the...
Apr 21, 2022This vulnerability allows attackers to upload arbitrary files (including PHP shells) through the signature upload feature in the VikBooking WordPress ...
Apr 19, 2022CVE-2022-27262 is a critical arbitrary file upload vulnerability in Skipper v0.9.1 that allows attackers to upload malicious files and execute arbitra...
Apr 12, 2022CVE-2022-27952 is a critical arbitrary file upload vulnerability in PayloadCMS v0.15.0 that allows attackers to upload malicious SVG files containing ...
Apr 12, 2022CVE-2022-28397 is an arbitrary file upload vulnerability in Ghost CMS v4.42.0 that allows attackers to upload malicious files and potentially execute ...
Apr 12, 2022CVE-2022-27139 is an arbitrary file upload vulnerability in Ghost CMS v4.39.0 that allows authenticated users to upload SVG files containing malicious...
Apr 12, 2022CVE-2022-27260 is a critical arbitrary file upload vulnerability in ButterCMS v1.2.8 that allows attackers to upload malicious SVG files containing em...
Apr 12, 2022CVE-2022-27115 is a remote code execution vulnerability in elFinder file manager that allows attackers to bypass file upload restrictions by manipulat...
Apr 11, 2022CVE-2022-27477 is an arbitrary file upload vulnerability in Newbee-Mall v1.0.0 that allows authenticated attackers to upload malicious files via the a...
Apr 10, 2022This vulnerability allows attackers to upload arbitrary PHP files to zbzcms v1.0 through the /zbzedit/php/zbz.php endpoint. Successful exploitation en...
Apr 10, 2022This vulnerability allows remote attackers to upload arbitrary files including PHP scripts to elFinder web file managers, potentially leading to remot...
Apr 7, 2022This CVE describes a file upload vulnerability in HorizontCMS that allows attackers to bypass PHP extension restrictions by uploading .htaccess and .h...
Apr 5, 2022CVE-2022-24136 is a critical vulnerability in Hospital Management System v1.0 that allows attackers to upload arbitrary PHP files via treatmentrecord....
Mar 31, 2022This critical vulnerability in Online Banking System Protect v1.0 allows attackers to upload malicious PHP files through the image upload function, le...
Mar 30, 2022This vulnerability allows remote attackers to upload malicious files to the Student Attendance Management System 1.0, potentially leading to remote co...
Mar 29, 2022This vulnerability allows attackers to upload malicious PHP files through taoCMS's File Management module, leading to remote code execution. It affect...
Mar 23, 2022This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Ninja Forms - File Uploads Extension plugin...
Mar 23, 2022OpenDocMan 1.4.4 contains a critical file upload vulnerability that allows attackers to bypass MIME type restrictions and upload dangerous file types....
Mar 18, 2022CVE-2021-45040 is an unrestricted file upload vulnerability in Spatie's Laravel Media Library Pro that allows remote attackers to upload executable fi...
Mar 17, 2022CVE-2022-25487 is a critical remote code execution vulnerability in Atom CMS v2.0 that allows attackers to upload malicious files via the /admin/uploa...
Mar 15, 2022CVE-2022-24651 is an unauthenticated arbitrary file upload vulnerability in sentcms 4.0.x that allows remote attackers to upload malicious PHP files t...
Mar 10, 2022About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,408 CVEs classified as CWE-434, with 700 rated critical and 593 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free