CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,420)
This vulnerability allows remote attackers to upload arbitrary PHP files to WordPress servers running the vulnerable YITH WooCommerce Gift Cards Premi...
Feb 22, 2021CVE-2021-26809 is a critical remote code execution vulnerability in PHPGurukul Car Rental Project version 2.0 that allows unauthenticated attackers to...
Feb 17, 2021This vulnerability in ProBot for Discord allows attackers to upload malicious files with double extensions (like .html.jpg) that are served with text/...
Feb 9, 2021CVE-2021-3378 is an arbitrary file upload vulnerability in FortiLogger that allows attackers to upload malicious files by sending a Content-Type: imag...
Feb 1, 2021This vulnerability allows attackers to upload arbitrary files to yccms 3.3 systems without proper validation, leading to remote code execution. Attack...
Feb 1, 2021This vulnerability allows unauthenticated attackers to execute arbitrary commands on NETGEAR NMS300 network management systems. Attackers can gain ful...
Dec 30, 2020This vulnerability allows remote attackers to execute arbitrary code on Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers by u...
Dec 17, 2020UCMS 1.5.0 contains an arbitrary file upload vulnerability (CWE-434) that allows attackers to upload malicious files to the server. This can lead to r...
Nov 30, 2020This vulnerability allows attackers to upload arbitrary PHP files to the Online Library Management System, leading to remote code execution. It affect...
Nov 17, 2020This vulnerability allows attackers to upload arbitrary files to the web server directory in Aviatrix Controller versions before R6.0.2483. This can l...
Nov 17, 2020CVE-2020-28140 is a critical arbitrary file upload vulnerability in SourceCodester Online Clothing Store 1.0 that allows attackers to upload malicious...
Nov 17, 2020This vulnerability allows attackers to upload malicious PHP files disguised as JPEG images to Microweber's admin panel. Attackers can execute arbitrar...
Nov 9, 2020This vulnerability in NVIDIA DGX servers allows attackers to upload malicious files to the BMC firmware, which can be automatically processed leading ...
Oct 29, 2020This vulnerability allows attackers to upload malicious PHP files through the car rental management system's image upload feature, leading to remote c...
Oct 28, 2020This vulnerability in Niushop B2B2C Multi-business basic version allows attackers to bypass administrator authentication, access the background upload...
Sep 30, 2020CVE-2020-23828 is a critical file upload vulnerability in SourceCodester Online Course Registration v1.0 that allows remote attackers to upload malici...
Sep 15, 2020This vulnerability allows unauthenticated attackers to upload arbitrary files to the Vehicle Image Upload component in Car Rental Management System v1...
Sep 9, 2020CVE-2020-24202 is an arbitrary file upload vulnerability in the House Rental v1.0 PHP application that allows regular users to upload malicious files,...
Aug 27, 2020This vulnerability allows remote attackers to upload and execute arbitrary PHP code on Navigate CMS servers by exploiting insufficient file extension ...
Jun 15, 2020This vulnerability in the WordPress Drag and Drop Multiple File Uploader plugin allows attackers to upload PHP files and execute arbitrary code on aff...
Jun 8, 2020This vulnerability in Foxit PhantomPDF allows attackers to execute arbitrary applications by embedding executable files within PDF portfolios. Users o...
Jun 4, 2020This vulnerability allows local attackers to execute arbitrary code with SYSTEM privileges by exploiting the AnchorFree VPN SDK service. The service a...
May 21, 2020This vulnerability in asbplayer v1.13.0 allows attackers to upload malicious subtitle files that can execute arbitrary code on the system. Users of as...
Feb 25, 2026This vulnerability allows remote attackers to execute arbitrary code on ManageEngine Exchange Reporter Plus servers through the Content Search module....
Jun 9, 2025This CVE describes an unauthenticated file upload vulnerability in SAP systems that allows attackers to upload malicious files to the server. When vic...
May 14, 2024Traccar GPS tracking system versions 5.1 through 5.12 contain an unrestricted file upload vulnerability in the device image upload API. Attackers can ...
Apr 10, 2024This vulnerability allows authenticated users with upload permissions in Admidio to execute arbitrary PHP code on the server by uploading malicious .p...
May 20, 2021Explorance Blue versions before 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. This allows at...
Jan 28, 2026This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the Xpro Elementor Addons plugin. Attack...
Jan 22, 2026This vulnerability allows high-privileged attackers to upload dangerous file types to ColdFusion servers without authentication, potentially leading t...
Dec 10, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Advanced Settings plugin. Attack...
Nov 6, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Bulk Featured Image plugin. Atta...
Sep 5, 2025phpgurukul Online Shopping Portal 2.0 contains an arbitrary file upload vulnerability in the admin product upload functionality. Attackers can upload ...
Sep 3, 2025This vulnerability allows attackers to upload malicious files to WordPress sites using the vcita Online Booking & Scheduling Calendar plugin. Attacker...
Aug 20, 2025An authenticated arbitrary file upload vulnerability in SMA 100 series web management interface allows attackers with administrative privileges to upl...
Jul 23, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Groundhogg plugin. Attackers can...
Jul 16, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Bulk Featured Image plugin. Atta...
Jul 4, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable AiBud WP plugin. Atta...
Jul 3, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the File Manager Plugin. Attackers can g...
Jun 27, 2025The ZoomSounds WordPress plugin before version 6.05 contains an unrestricted file upload vulnerability. Unauthenticated attackers can upload arbitrary...
Jun 25, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the BEAF plugin. Attackers can gain full...
May 7, 2025This vulnerability allows attackers to upload malicious files to WordPress sites using the I Draw plugin. Attackers can execute arbitrary code, potent...
Apr 17, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the Kadence WooComme...
Apr 16, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress sites using the affected plugin. It ...
Apr 10, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable LABCAT Processing Projects Word...
Apr 10, 2025CVE-2025-31002 is an arbitrary file upload vulnerability in the Squeeze WordPress plugin that allows attackers to upload malicious files to vulnerable...
Apr 9, 2025This vulnerability allows attackers to upload malicious files to WordPress sites using the CMP – Coming Soon & Maintenance plugin. Attackers can ach...
Apr 4, 2025This vulnerability in PyTorch Lightning's LightningApp allows attackers to write arbitrary files via a crafted filename at the /api/v1/upload_file/ en...
Mar 20, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the ThemeEgg ToolKit plugin. Attackers c...
Mar 11, 2025This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Tourfic plugin. It affects all W...
Jan 24, 2025About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,420 CVEs classified as CWE-434, with 703 rated critical and 602 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free