CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,408
Total CVEs
700
Critical
593
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,408)

CVE-2022-48079
9.8

CVE-2022-48079 is a critical privilege escalation vulnerability in Monnai aaPanel host system v1.5 that allows attackers to upload malicious PHP files...

Feb 2, 2023
CVE-2022-47769
9.8

CVE-2022-47769 is an arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 that allows unauthenticated attackers to upload m...

Feb 1, 2023
CVE-2022-34496
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to the Hiby R3 PRO device via its web server interface. This affects all...

Jul 29, 2022
CVE-2022-34115
9.8

DataEase v1.11.1 contains an arbitrary file write vulnerability via the dataSourceId parameter. This allows attackers to write arbitrary files to the ...

Jul 22, 2022
CVE-2021-36711
9.8

CVE-2021-36711 is a critical remote code execution vulnerability in OctoBot's WebInterface that allows attackers to upload malicious Tentacles (plugin...

Jul 16, 2022
CVE-2022-28369
9.8

This vulnerability allows remote attackers on the local network to execute arbitrary code as root on Verizon 5G Home LVSKIHP InDoorUnit devices. The d...

Jul 14, 2022
CVE-2022-1952
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the Free Booking Plugin for Hotels, Restauran...

Jul 11, 2022
CVE-2021-29281
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to GFI Mail Archiver servers via insecure Telerik Web UI components. It ...

Jul 7, 2022
CVE-2022-32994
9.8

Halo CMS v1.5.3 contains an arbitrary file upload vulnerability in the /api/admin/attachments/upload endpoint that allows authenticated attackers to u...

Jun 27, 2022
CVE-2021-38945
9.8

CVE-2021-38945 is a critical vulnerability in IBM Cognos Analytics that allows remote attackers to upload arbitrary files due to improper content vali...

Jun 24, 2022
CVE-2021-40954
9.8

Laiketui 3.5.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the server. This can lead to remote ...

Jun 23, 2022
CVE-2021-40940
9.8

Monstra CMS 3.0.4 has an unrestricted file upload vulnerability due to insufficient filtering of PHP file extensions. Attackers can upload malicious P...

Jun 15, 2022
CVE-2022-32019
9.8

Car Rental Management System v1.0 contains an unrestricted file upload vulnerability in the admin/ajax.php endpoint that allows remote attackers to ex...

Jun 2, 2022
CVE-2022-30808
9.8

EliteCMS 1.0.1 contains a critical vulnerability in the admin/manage_uploads.php file that allows authenticated attackers to upload malicious files an...

Jun 2, 2022
CVE-2022-30506
9.8

CVE-2022-30506 is an arbitrary file upload vulnerability in MCMS 5.2.7 that allows attackers to upload malicious ZIP files containing executable code....

Jun 2, 2022
CVE-2022-24239
9.8

ACEweb Online Portal 3.5.065 contains an unrestricted file upload vulnerability in the attachments.awp component. This allows attackers to upload mali...

Jun 2, 2022
CVE-2022-29632
9.8

This vulnerability allows attackers to upload malicious files to the Roncoo Education platform's course API endpoint, which can lead to remote code ex...

May 26, 2022
CVE-2021-42654
9.8

SiteServer CMS versions before 5.1 contain an unrestricted file upload vulnerability that allows attackers to upload malicious files and execute arbit...

May 24, 2022
CVE-2022-30887
9.8

Pharmacy Management System v1.0 contains a critical remote code execution vulnerability in the /php_action/editProductImage.php component. Attackers c...

May 20, 2022
CVE-2022-28104
9.8

Foxit PDF Editor v11.3.1 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the system. This affects a...

May 20, 2022
CVE-2022-29351
9.8

CVE-2022-29351 is an arbitrary file upload vulnerability in TiddlyWiki5 v5.2.2 that allows attackers to upload malicious SVG files containing JavaScri...

May 16, 2022
CVE-2022-29354
9.8

CVE-2022-29354 is an arbitrary file upload vulnerability in Keystone v4.2.1 that allows attackers to upload malicious files and execute arbitrary code...

May 16, 2022
CVE-2021-42967
9.8

This vulnerability allows attackers to upload malicious JSP files without restrictions in novel-plus's file controller. It affects all versions of nov...

May 13, 2022
CVE-2022-30448
9.8

CVE-2022-30448 is an unauthenticated file upload vulnerability in Hospital Management System (HMS) 1.0 that allows attackers to upload arbitrary files...

May 11, 2022
CVE-2022-28120
9.8

This vulnerability allows attackers to upload malicious files to the Open Virtual Simulation Experiment Teaching Management Platform software version ...

May 5, 2022
CVE-2022-28568
9.8

CVE-2022-28568 is a critical vulnerability in Sourcecodester Doctor's Appointment System 1.0 that allows authenticated administrators to upload malici...

May 4, 2022
CVE-2022-29347
9.8

CVE-2022-29347 is an arbitrary file upload vulnerability in Web@rchiv 1.0 that allows attackers to upload malicious PHP files. This enables remote cod...

May 4, 2022
CVE-2021-41921
9.8

CVE-2021-41921 is an unrestricted file upload vulnerability in novel-plus V3.6.1 that allows attackers to upload malicious files with arbitrary extens...

Apr 28, 2022
CVE-2022-27468
9.8

CVE-2022-27468 is a critical arbitrary file upload vulnerability in Monstaftp v2.10.3 that allows attackers to upload malicious files to the web serve...

Apr 26, 2022
CVE-2022-28021
9.8

CVE-2022-28021 is a remote code execution vulnerability in Purchase Order Management System v1.0, allowing attackers to execute arbitrary code via the...

Apr 21, 2022
CVE-2022-27862
9.8

This vulnerability allows attackers to upload arbitrary files (including PHP shells) through the signature upload feature in the VikBooking WordPress ...

Apr 19, 2022
CVE-2022-27262
9.8

CVE-2022-27262 is a critical arbitrary file upload vulnerability in Skipper v0.9.1 that allows attackers to upload malicious files and execute arbitra...

Apr 12, 2022
CVE-2022-27952
9.8

CVE-2022-27952 is a critical arbitrary file upload vulnerability in PayloadCMS v0.15.0 that allows attackers to upload malicious SVG files containing ...

Apr 12, 2022
CVE-2022-28397
9.8

CVE-2022-28397 is an arbitrary file upload vulnerability in Ghost CMS v4.42.0 that allows attackers to upload malicious files and potentially execute ...

Apr 12, 2022
CVE-2022-27139
9.8

CVE-2022-27139 is an arbitrary file upload vulnerability in Ghost CMS v4.39.0 that allows authenticated users to upload SVG files containing malicious...

Apr 12, 2022
CVE-2022-27260
9.8

CVE-2022-27260 is a critical arbitrary file upload vulnerability in ButterCMS v1.2.8 that allows attackers to upload malicious SVG files containing em...

Apr 12, 2022
CVE-2022-27115
9.8

CVE-2022-27115 is a remote code execution vulnerability in elFinder file manager that allows attackers to bypass file upload restrictions by manipulat...

Apr 11, 2022
CVE-2022-27477
9.8

CVE-2022-27477 is an arbitrary file upload vulnerability in Newbee-Mall v1.0.0 that allows authenticated attackers to upload malicious files via the a...

Apr 10, 2022
CVE-2022-27131
9.8

This vulnerability allows attackers to upload arbitrary PHP files to zbzcms v1.0 through the /zbzedit/php/zbz.php endpoint. Successful exploitation en...

Apr 10, 2022
CVE-2021-43421
9.8

This vulnerability allows remote attackers to upload arbitrary files including PHP scripts to elFinder web file managers, potentially leading to remot...

Apr 7, 2022
CVE-2021-28428
9.8

This CVE describes a file upload vulnerability in HorizontCMS that allows attackers to bypass PHP extension restrictions by uploading .htaccess and .h...

Apr 5, 2022
CVE-2022-24136
9.8

CVE-2022-24136 is a critical vulnerability in Hospital Management System v1.0 that allows attackers to upload arbitrary PHP files via treatmentrecord....

Mar 31, 2022
CVE-2022-26645
9.8

This critical vulnerability in Online Banking System Protect v1.0 allows attackers to upload malicious PHP files through the image upload function, le...

Mar 30, 2022
CVE-2021-45865
9.8

This vulnerability allows remote attackers to upload malicious files to the Student Attendance Management System 1.0, potentially leading to remote co...

Mar 29, 2022
CVE-2022-23880
9.8

This vulnerability allows attackers to upload malicious PHP files through taoCMS's File Management module, leading to remote code execution. It affect...

Mar 23, 2022
CVE-2022-0888
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Ninja Forms - File Uploads Extension plugin...

Mar 23, 2022
CVE-2021-45834
9.8

OpenDocMan 1.4.4 contains a critical file upload vulnerability that allows attackers to bypass MIME type restrictions and upload dangerous file types....

Mar 18, 2022
CVE-2021-45040
9.8

CVE-2021-45040 is an unrestricted file upload vulnerability in Spatie's Laravel Media Library Pro that allows remote attackers to upload executable fi...

Mar 17, 2022
CVE-2022-25487
9.8

CVE-2022-25487 is a critical remote code execution vulnerability in Atom CMS v2.0 that allows attackers to upload malicious files via the /admin/uploa...

Mar 15, 2022
CVE-2022-24651
9.8

CVE-2022-24651 is an unauthenticated arbitrary file upload vulnerability in sentcms 4.0.x that allows remote attackers to upload malicious PHP files t...

Mar 10, 2022

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,408 CVEs classified as CWE-434, with 700 rated critical and 593 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free