CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,420
Total CVEs
703
Critical
602
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Apache 7
5 Phpgurukul 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Mingsoft 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,420)

CVE-2021-3120
9.8

This vulnerability allows remote attackers to upload arbitrary PHP files to WordPress servers running the vulnerable YITH WooCommerce Gift Cards Premi...

Feb 22, 2021
CVE-2021-26809
9.8

CVE-2021-26809 is a critical remote code execution vulnerability in PHPGurukul Car Rental Project version 2.0 that allows unauthenticated attackers to...

Feb 17, 2021
CVE-2021-26918
9.8

This vulnerability in ProBot for Discord allows attackers to upload malicious files with double extensions (like .html.jpg) that are served with text/...

Feb 9, 2021
CVE-2021-3378
9.8

CVE-2021-3378 is an arbitrary file upload vulnerability in FortiLogger that allows attackers to upload malicious files by sending a Content-Type: imag...

Feb 1, 2021
CVE-2020-20287
9.8

This vulnerability allows attackers to upload arbitrary files to yccms 3.3 systems without proper validation, leading to remote code execution. Attack...

Feb 1, 2021
CVE-2020-35797
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on NETGEAR NMS300 network management systems. Attackers can gain ful...

Dec 30, 2020
CVE-2020-25010
9.8

This vulnerability allows remote attackers to execute arbitrary code on Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers by u...

Dec 17, 2020
CVE-2020-25537
9.8

UCMS 1.5.0 contains an arbitrary file upload vulnerability (CWE-434) that allows attackers to upload malicious files to the server. This can lead to r...

Nov 30, 2020
CVE-2020-28130
9.8

This vulnerability allows attackers to upload arbitrary PHP files to the Online Library Management System, leading to remote code execution. It affect...

Nov 17, 2020
CVE-2020-26553
9.8

This vulnerability allows attackers to upload arbitrary files to the web server directory in Aviatrix Controller versions before R6.0.2483. This can l...

Nov 17, 2020
CVE-2020-28140
9.8

CVE-2020-28140 is a critical arbitrary file upload vulnerability in SourceCodester Online Clothing Store 1.0 that allows attackers to upload malicious...

Nov 17, 2020
CVE-2020-23138
9.8

This vulnerability allows attackers to upload malicious PHP files disguised as JPEG images to Microweber's admin panel. Attackers can execute arbitrar...

Nov 9, 2020
CVE-2020-11486
9.8

This vulnerability in NVIDIA DGX servers allows attackers to upload malicious files to the BMC firmware, which can be automatically processed leading ...

Oct 29, 2020
CVE-2020-27956
9.8

This vulnerability allows attackers to upload malicious PHP files through the car rental management system's image upload feature, leading to remote c...

Oct 28, 2020
CVE-2020-19672
9.8

This vulnerability in Niushop B2B2C Multi-business basic version allows attackers to bypass administrator authentication, access the background upload...

Sep 30, 2020
CVE-2020-23828
9.8

CVE-2020-23828 is a critical file upload vulnerability in SourceCodester Online Course Registration v1.0 that allows remote attackers to upload malici...

Sep 15, 2020
CVE-2020-24199
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to the Vehicle Image Upload component in Car Rental Management System v1...

Sep 9, 2020
CVE-2020-24202
9.8

CVE-2020-24202 is an arbitrary file upload vulnerability in the House Rental v1.0 PHP application that allows regular users to upload malicious files,...

Aug 27, 2020
CVE-2020-14067
9.8

This vulnerability allows remote attackers to upload and execute arbitrary PHP code on Navigate CMS servers by exploiting insufficient file extension ...

Jun 15, 2020
CVE-2020-12800
9.8

This vulnerability in the WordPress Drag and Drop Multiple File Uploader plugin allows attackers to upload PHP files and execute arbitrary code on aff...

Jun 8, 2020
CVE-2018-21244
9.8

This vulnerability in Foxit PhantomPDF allows attackers to execute arbitrary applications by embedding executable files within PDF portfolios. Users o...

Jun 4, 2020
CVE-2020-12828
9.8

This vulnerability allows local attackers to execute arbitrary code with SYSTEM privileges by exploiting the AnchorFree VPN SDK service. The service a...

May 21, 2020
CVE-2025-69771
9.6

This vulnerability in asbplayer v1.13.0 allows attackers to upload malicious subtitle files that can execute arbitrary code on the system. Users of as...

Feb 25, 2026
CVE-2025-3835
9.6

This vulnerability allows remote attackers to execute arbitrary code on ManageEngine Exchange Reporter Plus servers through the Content Search module....

Jun 9, 2025
CVE-2024-33006
9.6

This CVE describes an unauthenticated file upload vulnerability in SAP systems that allows attackers to upload malicious files to the server. When vic...

May 14, 2024
CVE-2024-31214
9.6

Traccar GPS tracking system versions 5.1 through 5.12 contain an unrestricted file upload vulnerability in the device image upload API. Attackers can ...

Apr 10, 2024
CVE-2021-32630
9.6

This vulnerability allows authenticated users with upload permissions in Admidio to execute arbitrary PHP code on the server by uploading malicious .p...

May 20, 2021
CVE-2025-57794
9.1

Explorance Blue versions before 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. This allows at...

Jan 28, 2026
CVE-2025-69312
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the Xpro Elementor Addons plugin. Attack...

Jan 22, 2026
CVE-2025-61808
9.1

This vulnerability allows high-privileged attackers to upload dangerous file types to ColdFusion servers without authentication, potentially leading t...

Dec 10, 2025
CVE-2025-58996
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Advanced Settings plugin. Attack...

Nov 6, 2025
CVE-2025-58819
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Bulk Featured Image plugin. Atta...

Sep 5, 2025
CVE-2025-57148
9.1

phpgurukul Online Shopping Portal 2.0 contains an arbitrary file upload vulnerability in the admin product upload functionality. Attackers can upload ...

Sep 3, 2025
CVE-2025-54677
9.1

This vulnerability allows attackers to upload malicious files to WordPress sites using the vcita Online Booking & Scheduling Calendar plugin. Attacker...

Aug 20, 2025
CVE-2025-40599
9.1

An authenticated arbitrary file upload vulnerability in SMA 100 series web management interface allows attackers with administrative privileges to upl...

Jul 23, 2025
CVE-2025-48300
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Groundhogg plugin. Attackers can...

Jul 16, 2025
CVE-2025-28951
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Bulk Featured Image plugin. Atta...

Jul 4, 2025
CVE-2025-23968
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable AiBud WP plugin. Atta...

Jul 3, 2025
CVE-2025-53260
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the File Manager Plugin. Attackers can g...

Jun 27, 2025
CVE-2021-4457
9.1

The ZoomSounds WordPress plugin before version 6.05 contains an unrestricted file upload vulnerability. Unauthenticated attackers can upload arbitrary...

Jun 25, 2025
CVE-2025-47549
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the BEAF plugin. Attackers can gain full...

May 7, 2025
CVE-2025-39436
9.1

This vulnerability allows attackers to upload malicious files to WordPress sites using the I Draw plugin. Attackers can execute arbitrary code, potent...

Apr 17, 2025
CVE-2025-39557
9.1

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the Kadence WooComme...

Apr 16, 2025
CVE-2025-32202
9.1

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress sites using the affected plugin. It ...

Apr 10, 2025
CVE-2025-32206
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the vulnerable LABCAT Processing Projects Word...

Apr 10, 2025
CVE-2025-31002
9.1

CVE-2025-31002 is an arbitrary file upload vulnerability in the Squeeze WordPress plugin that allows attackers to upload malicious files to vulnerable...

Apr 9, 2025
CVE-2025-32118
9.1

This vulnerability allows attackers to upload malicious files to WordPress sites using the CMP – Coming Soon & Maintenance plugin. Attackers can ach...

Apr 4, 2025
CVE-2024-8019
9.1

This vulnerability in PyTorch Lightning's LightningApp allows attackers to write arbitrary files via a crafted filename at the /api/v1/upload_file/ en...

Mar 20, 2025
CVE-2025-28915
EPSS 21.4% 9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the ThemeEgg ToolKit plugin. Attackers c...

Mar 11, 2025
CVE-2025-24650
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Tourfic plugin. It affects all W...

Jan 24, 2025

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,420 CVEs classified as CWE-434, with 703 rated critical and 602 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free