CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,415
Total CVEs
700
Critical
600
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,415)

CVE-2021-38753
9.8

CVE-2021-38753 is a critical unrestricted file upload vulnerability in Simple Image Gallery Web App that allows attackers to upload malicious files li...

Aug 16, 2021
CVE-2020-20979
9.8

This vulnerability allows attackers to upload arbitrary files to LJCMS v4.3 web servers through the move_uploaded_file() function, potentially leading...

Aug 12, 2021
CVE-2021-24499
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files, including PHP scripts, to WordPress sites using the Workreap theme. The...

Aug 9, 2021
CVE-2020-28088
9.8

This vulnerability allows attackers to upload arbitrary files to the jeecg-boot CMS system through the /jeecg-boot/sys/common/upload endpoint. Attacke...

Aug 6, 2021
CVE-2021-36622
9.8

CVE-2021-36622 allows unauthenticated attackers to upload malicious PHP files disguised as images to the admin panel of Sourcecodester Online Covid Va...

Aug 3, 2021
CVE-2021-25200
9.8

This CVE describes an arbitrary file upload vulnerability in SourceCodester Learning Management System v1.0, allowing attackers to upload malicious fi...

Jul 30, 2021
CVE-2021-25203
9.8

CVE-2021-25203 is an arbitrary file upload vulnerability in Victor CMS v1.0 that allows attackers to upload malicious files to the server. This vulner...

Jul 23, 2021
CVE-2021-25206
9.8

This vulnerability allows attackers to upload arbitrary files to the Responsive Ordering System v1.0 via Product_model.php, potentially leading to rem...

Jul 23, 2021
CVE-2021-25207
9.8

CVE-2021-25207 is an arbitrary file upload vulnerability in SourceCodester E-Commerce Website v1.0 that allows attackers to upload malicious files to ...

Jul 23, 2021
CVE-2021-25211
9.8

CVE-2021-25211 is an arbitrary file upload vulnerability in SourceCodester Ordering System v1.0 that allows attackers to upload malicious files to the...

Jul 22, 2021
CVE-2021-25210
9.8

This vulnerability allows attackers to upload arbitrary files to the Alumni Management System, which can lead to remote code execution. It affects Sou...

Jul 22, 2021
CVE-2021-35963
9.8

CVE-2021-35963 is an unauthenticated remote code execution vulnerability in the Orca HCM digital learning platform's file upload function. Attackers c...

Jul 19, 2021
CVE-2021-30118
9.8

CVE-2021-30118 is an unauthenticated arbitrary file upload vulnerability in Kaseya VSA that allows remote attackers to upload malicious ASP.NET files ...

Jul 9, 2021
CVE-2021-32538
9.8

CVE-2021-32538 is an unauthenticated remote code execution vulnerability in ARTWARE CMS. Attackers can upload arbitrary files without authentication t...

Jul 7, 2021
CVE-2021-34623
9.8

This critical vulnerability in the ProfilePress WordPress plugin allows unauthenticated attackers to upload arbitrary files during user registration o...

Jul 7, 2021
CVE-2021-34074
9.8

PandoraFMS versions up to 7.54 contain an arbitrary file upload vulnerability in the File Manager component. Attackers can bypass built-in protections...

Jun 25, 2021
CVE-2020-21786
9.8

This vulnerability allows remote attackers to execute arbitrary code on IBOS 4.5.4 Open systems through arbitrary file inclusion in the CronController...

Jun 24, 2021
CVE-2020-21787
9.8

CRMEB versions 3.1.0+ contain an unrestricted file upload vulnerability in the UploadService.php component that allows attackers to upload malicious f...

Jun 24, 2021
CVE-2010-1433
9.8

This vulnerability allows attackers to upload arbitrary files to Joomla! websites due to insufficient input validation in the installer migration scri...

Jun 21, 2021
CVE-2021-24376
9.8

This vulnerability in the Autoptimize WordPress plugin allows attackers to upload malicious PHP files through the Import Settings feature, bypassing p...

Jun 21, 2021
CVE-2021-24370
9.8

The Fancy Product Designer WordPress plugin before version 4.6.9 contains an unauthenticated arbitrary file upload vulnerability. This allows attacker...

Jun 21, 2021
CVE-2020-19510
9.8

CVE-2020-19510 is an arbitrary file upload vulnerability in Textpattern CMS that allows authenticated attackers to upload malicious files to the serve...

Jun 21, 2021
CVE-2013-20002
9.8

This vulnerability allows remote attackers to upload and execute arbitrary PHP code via the Themify framework in the Elemin WordPress theme. Attackers...

Jun 17, 2021
CVE-2020-35760
9.8

CVE-2020-35760 is an unrestricted file upload vulnerability in bloofoxCMS that allows attackers to upload malicious PHP files. This can lead to remote...

Jun 16, 2021
CVE-2021-26473
9.8

CVE-2021-26473 is a critical vulnerability in VembuBDR and VembuOffsiteDR backup software that allows unauthenticated attackers to write arbitrary fil...

Jun 8, 2021
CVE-2021-31703
9.8

Frontier ichris versions through 5.18 allow authenticated users to upload malicious executable files that can be downloaded and executed by other user...

May 29, 2021
CVE-2021-27459
9.8

This vulnerability allows attackers to upload unvalidated files to Emerson Rosemount X-STREAM Gas Analyzer webservers, enabling remote code execution....

May 20, 2021
CVE-2020-18166
9.8

This vulnerability allows remote attackers to upload arbitrary files to LAOBANCMS v2.0 by exploiting an unrestricted file upload flaw. Attackers can u...

May 14, 2021
CVE-2021-24284
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary ZIP files containing malicious PHP scripts to WordPress sites using the Kaswar...

May 14, 2021
CVE-2020-20092
9.8

This vulnerability allows remote attackers to upload malicious PHP files disguised as JPEG images to ArticleCMS 1.0, enabling arbitrary code execution...

May 13, 2021
CVE-2020-28063
9.8

CVE-2020-28063 is a critical file upload vulnerability in ArticleCMS that allows attackers to upload malicious files and execute arbitrary code on the...

May 13, 2021
CVE-2020-23790
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to servers running the Golo Laravel theme v1.1.5. This can lead to remot...

May 12, 2021
CVE-2021-32089
9.8

CVE-2021-32089 allows unauthenticated attackers to upload arbitrary files to Zebra FX9500 RFID Reader filesystems, which can then be accessed via the ...

May 11, 2021
CVE-2021-24236
9.8

The Imagements WordPress plugin through version 1.2.5 has an unauthenticated arbitrary file upload vulnerability that allows remote attackers to uploa...

May 6, 2021
CVE-2020-19113
9.8

This vulnerability allows attackers to upload arbitrary files to the Online Book Store v1.0 web application through the admin_add.php endpoint. Succes...

May 6, 2021
CVE-2020-23083
9.8

CVE-2020-23083 is a critical unrestricted file upload vulnerability in JEECG that allows remote attackers to upload malicious files without proper val...

May 3, 2021
CVE-2020-21452
9.8

This is a critical unauthenticated file upload vulnerability in Uniview ISC2500-S surveillance systems that allows attackers to upload arbitrary malic...

Apr 29, 2021
CVE-2021-24240
9.8

This vulnerability allows unauthenticated remote attackers to upload arbitrary files via the Business Hours Pro WordPress plugin's manual update funct...

Apr 22, 2021
CVE-2020-29592
9.8

This vulnerability allows attackers to upload dangerous executable files through Orchard's TinyMCE editor, bypassing file type restrictions. It affect...

Apr 14, 2021
CVE-2021-24222
9.8

The WP-Curriculo Vitae Free WordPress plugin through version 6.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers...

Apr 12, 2021
CVE-2021-28173
9.8

CVE-2021-28173 is an unauthenticated remote code execution vulnerability in Vangene deltaFlow E-platform's file upload function. Attackers can upload ...

Apr 6, 2021
CVE-2021-24212
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the WooCommerce Help Scout plugin before versio...

Apr 5, 2021
CVE-2021-24171
9.8

This vulnerability in the WooCommerce Upload Files WordPress plugin allows attackers to bypass file extension filtering and upload malicious PHP files...

Apr 5, 2021
CVE-2020-21585
9.8

CVE-2020-21585 is a critical vulnerability in emlog v6.0.0 that allows authenticated users to upload malicious PHP webshells via the zip plugin module...

Apr 2, 2021
CVE-2021-27274
9.8

This is an unauthenticated remote code execution vulnerability in NETGEAR ProSAFE Network Management System. Attackers can upload malicious files and ...

Mar 29, 2021
CVE-2021-27817
9.8

This CVE describes a remote code execution vulnerability in ShopXO e-commerce platform version 1.9.3. Attackers can upload malicious PHAR files disgui...

Mar 15, 2021
CVE-2021-27964
9.8

CVE-2021-27964 allows unauthenticated attackers to upload arbitrary files to SonLogger web servers via a specific endpoint. This can lead to remote co...

Mar 5, 2021
CVE-2021-27198
9.8

CVE-2021-27198 allows unauthenticated attackers to upload arbitrary files and execute code remotely on Visualware MyConnection Server installations. T...

Feb 26, 2021
CVE-2021-3120
9.8

This vulnerability allows remote attackers to upload arbitrary PHP files to WordPress servers running the vulnerable YITH WooCommerce Gift Cards Premi...

Feb 22, 2021
CVE-2021-26809
9.8

CVE-2021-26809 is a critical remote code execution vulnerability in PHPGurukul Car Rental Project version 2.0 that allows unauthenticated attackers to...

Feb 17, 2021

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,415 CVEs classified as CWE-434, with 700 rated critical and 600 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free