CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,411
Total CVEs
700
Critical
596
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,411)

CVE-2022-25016
9.8

CVE-2022-25016 is a critical arbitrary file upload vulnerability in Home Owners Collection Management System v1.0 that allows attackers to upload mali...

Mar 2, 2022
CVE-2022-25411
9.8

This vulnerability allows remote attackers to execute arbitrary PHP code on Maxsite CMS v180 installations by uploading a crafted PHP file to the /adm...

Feb 28, 2022
CVE-2022-24984
9.8

This vulnerability allows remote unauthenticated attackers to upload executable files to websites using vulnerable JQueryForm.com forms, leading to re...

Feb 16, 2022
CVE-2021-22803
9.8

This vulnerability allows attackers to upload malicious files to Schneider Electric's Interactive Graphical SCADA System Data Collector (dc.exe), pote...

Feb 11, 2022
CVE-2022-23329
9.8

This vulnerability in UJCMS Jspxcms allows attackers to execute arbitrary system commands by uploading malicious files that exploit a dangerous FreeMa...

Feb 4, 2022
CVE-2021-46428
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on systems running Sourcecodester Simple Chatbot Application 1.0 ...

Jan 27, 2022
CVE-2021-46386
9.8

This CVE describes a critical file upload vulnerability in mingSoft MCMS content management system that allows remote attackers to upload malicious JS...

Jan 26, 2022
CVE-2022-23315
9.8

MCMS v5.2.4 contains an arbitrary file upload vulnerability in the /ms/template/writeFileContent.do endpoint that allows attackers to upload malicious...

Jan 21, 2022
CVE-2021-46013
9.8

This vulnerability allows attackers to upload arbitrary PHP files to the school management software's upload directory, enabling remote code execution...

Jan 18, 2022
CVE-2021-44031
9.8

CVE-2021-44031 is a critical pre-authentication remote code execution vulnerability in Quest KACE Desktop Authority. Attackers can upload malicious AS...

Dec 22, 2021
CVE-2021-44159
9.8

This vulnerability allows unauthenticated remote attackers to upload arbitrary files, including webshells, to 4MOSAn GCB Doctor systems. Attackers can...

Dec 20, 2021
CVE-2021-44164
9.8

CVE-2021-44164 is a critical vulnerability in Chain Sea AI chatbot systems that allows unauthenticated remote attackers to bypass file upload restrict...

Dec 20, 2021
CVE-2021-41560
9.8

OpenCATS versions through 0.9.6 contain an unrestricted file upload vulnerability in lib/FileUtility.php that allows remote attackers to upload execut...

Dec 15, 2021
CVE-2021-40883
9.8

This vulnerability allows unauthenticated attackers to upload malicious PHP files through the plugin upload functionality in emlog, leading to remote ...

Dec 14, 2021
CVE-2021-43117
9.8

CVE-2021-43117 is a critical file upload vulnerability in FastAdmin v1.2.1 that allows attackers to upload malicious files and execute arbitrary code ...

Dec 13, 2021
CVE-2021-27860
9.8

This vulnerability allows remote, unauthenticated attackers to upload arbitrary files to any location on the filesystem of FatPipe WARP, IPVPN, and MP...

Dec 8, 2021
CVE-2021-42099
9.8

This vulnerability allows unauthenticated attackers to upload malicious files to Zoho ManageEngine M365 Manager Plus servers, leading to remote code e...

Nov 30, 2021
CVE-2021-44093
9.8

CVE-2021-44093 is a critical remote command execution vulnerability in zrlog 2.2.2 that allows attackers to bypass file upload restrictions and upload...

Nov 28, 2021
CVE-2021-43617
9.8

This vulnerability allows attackers to upload malicious .phar files that execute PHP code on Laravel applications running on Debian-based systems. It ...

Nov 14, 2021
CVE-2021-28023
9.8

This vulnerability allows authenticated attackers to upload malicious ZIP files containing JSP code through ServiceTonic's Service import feature. Whe...

Nov 8, 2021
CVE-2021-42669
9.8

This CVE describes a critical file upload vulnerability in Sourcecodester Engineers Online Portal that allows attackers to upload PHP webshells to exe...

Nov 5, 2021
CVE-2020-18261
9.8

CVE-2020-18261 is a critical arbitrary file upload vulnerability in ED01-CMS v1.0 that allows attackers to upload malicious files through the image up...

Nov 3, 2021
CVE-2021-41646
9.8

This vulnerability allows remote attackers to execute arbitrary code on Sourcecodester Online Reviewer System 1.0 by uploading malicious PHP files dis...

Oct 29, 2021
CVE-2021-41644
9.8

This vulnerability allows attackers to upload malicious PHP files disguised as images to the Online Food Ordering System, bypassing file upload filter...

Oct 29, 2021
CVE-2021-36547
9.8

This vulnerability allows remote attackers to execute arbitrary code on systems running Mara v7.5 by uploading a crafted PHP file to the /codebase/dir...

Oct 28, 2021
CVE-2021-41566
9.8

CVE-2021-41566 is an unauthenticated remote code execution vulnerability in TadTools file upload functionality. Attackers can upload arbitrary files w...

Oct 8, 2021
CVE-2021-37762
9.8

CVE-2021-37762 is a critical vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to overwrite arbitrary files on the server, leadi...

Oct 7, 2021
CVE-2021-37919
9.8

This vulnerability allows attackers to upload arbitrary files to Zoho ManageEngine ADManager Plus servers, which can lead to remote code execution. It...

Oct 7, 2021
CVE-2021-37921
9.8

CVE-2021-37921 is a critical vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to upload arbitrary files without restrictions, l...

Oct 7, 2021
CVE-2021-37923
9.8

CVE-2021-37923 is a critical vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to upload arbitrary files without restrictions, l...

Oct 7, 2021
CVE-2021-37926
9.8

CVE-2021-37926 is a critical unrestricted file upload vulnerability in Zoho ManageEngine ADManager Plus that allows attackers to upload malicious file...

Oct 7, 2021
CVE-2021-37929
9.8

This vulnerability in Zoho ManageEngine ADManager Plus allows attackers to upload arbitrary files without restrictions, leading to remote code executi...

Oct 7, 2021
CVE-2021-37931
9.8

This vulnerability allows attackers to upload arbitrary files to Zoho ManageEngine ADManager Plus servers, which can lead to remote code execution. It...

Oct 7, 2021
CVE-2021-3832
9.8

CVE-2021-3832 is a critical remote code execution vulnerability in Integria IMS version 5.0.92 that allows unauthenticated attackers to upload malicio...

Oct 7, 2021
CVE-2021-37761
9.8

This vulnerability allows attackers to upload malicious files to Zoho ManageEngine ADManager Plus servers without proper validation, leading to remote...

Sep 27, 2021
CVE-2021-37539
9.8

This vulnerability allows attackers to upload arbitrary files without restrictions in Zoho ManageEngine ADManager Plus, leading to remote code executi...

Sep 27, 2021
CVE-2021-26794
9.8

This vulnerability allows attackers to upload malicious PHP files through the upload.php script in FrogCMS SentCMS, leading to remote code execution a...

Sep 23, 2021
CVE-2020-21322
9.8

CVE-2020-21322 is an arbitrary file upload vulnerability in Feehi CMS that allows attackers to upload malicious PHP files. This can lead to remote cod...

Sep 15, 2021
CVE-2021-36581
9.8

Kooboo CMS 2.1.1.0 has an insecure file upload vulnerability that allows attackers to upload arbitrary files, including malicious ASPX web shells, to ...

Sep 14, 2021
CVE-2021-24493
9.8

This vulnerability allows unauthenticated attackers to upload malicious files (including PHP scripts) to WordPress sites running the Shopp plugin. Thi...

Sep 13, 2021
CVE-2020-19267
9.8

This vulnerability allows attackers to upload malicious PHP files to Dswjcms 1.6.4, leading to remote code execution. Attackers can take full control ...

Sep 9, 2021
CVE-2021-36440
9.8

This vulnerability allows remote attackers to upload arbitrary files to ShowDoc servers, which can lead to remote code execution. Attackers can exploi...

Sep 8, 2021
CVE-2020-19138
9.8

This vulnerability allows remote attackers to upload malicious files to DotCMS servers, leading to arbitrary code execution. Attackers can exploit thi...

Sep 8, 2021
CVE-2021-40531
9.8

CVE-2021-40531 is a vulnerability in Sketch design software that allows attackers to bypass macOS file quarantine protections through malicious librar...

Sep 6, 2021
CVE-2021-36356
9.8

CVE-2021-36356 is a critical remote code execution vulnerability in KRAMER VIAware software that allows attackers to execute arbitrary code by sending...

Aug 31, 2021
CVE-2021-32955
9.8

Delta Electronics DIAEnergie versions 1.7.5 and earlier contain an unrestricted file upload vulnerability that allows attackers to upload malicious fi...

Aug 30, 2021
CVE-2021-40175
9.8

CVE-2021-40175 is a critical vulnerability in Zoho ManageEngine Log360 that allows attackers to upload arbitrary files without authentication, leading...

Aug 29, 2021
CVE-2021-38613
9.8

This vulnerability allows attackers to upload arbitrary code through the Image Upload feature in NASCENT RemKon Device Manager, leading to remote code...

Aug 24, 2021
CVE-2020-18879
9.8

CVE-2020-18879 is an unrestricted file upload vulnerability in Bludit CMS v3.8.1 that allows remote attackers to upload malicious files via the upload...

Aug 20, 2021
CVE-2021-37608
9.8

This vulnerability allows attackers to upload malicious files to Apache OFBiz servers, which can lead to remote code execution. It affects Apache OFBi...

Aug 18, 2021

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,411 CVEs classified as CWE-434, with 700 rated critical and 596 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free