CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,426
Total CVEs
703
Critical
608
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Apache 7
5 Phpgurukul 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Mingsoft 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,426)

CVE-2025-23942
EPSS 43.2% 9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the WP Load Gallery plugin. Attacker...

Jan 22, 2025
CVE-2025-22723
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the UkrSolution Barcode Scanner with Inven...

Jan 21, 2025
CVE-2024-56249
EPSS 39.6% 9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPMasterToolKit plugin. Attackers ca...

Jan 2, 2025
CVE-2024-56054
9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPLMS plugin. It affects all WordPre...

Dec 18, 2024
CVE-2024-54285
9.1

This vulnerability allows attackers to upload malicious files, including web shells, to WordPress sites using the SeedProd Pro plugin. This can lead t...

Dec 16, 2024
CVE-2024-53863
9.1

This vulnerability in Synapse Matrix homeserver allows attackers to trigger processing of uncommon image formats by enabling dynamic_thumbnails or sen...

Dec 3, 2024
CVE-2024-52398
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Halyra CDI plugin. Attackers can upload malicious files l...

Nov 16, 2024
CVE-2024-47649
9.1

This vulnerability allows attackers to upload arbitrary files, including malicious scripts, to WordPress sites running the Iconize plugin. Successful ...

Oct 16, 2024
CVE-2024-6366
9.1

The User Profile Builder WordPress plugin before version 3.11.8 has an authorization vulnerability that allows unauthenticated users to upload media f...

Jul 29, 2024
CVE-2024-5450
9.1

The Bug Library WordPress plugin before version 2.1.1 has an unrestricted file upload vulnerability that allows unauthenticated attackers to upload PH...

Jul 13, 2024
CVE-2024-38736
9.1

This vulnerability allows attackers to upload malicious files to WordPress sites using the Realtyna Organic IDX plugin, potentially leading to code ex...

Jul 12, 2024
CVE-2024-38734
9.1

This vulnerability allows attackers to upload malicious files to WordPress sites using the Import Spreadsheets from Microsoft Excel plugin, potentiall...

Jul 12, 2024
CVE-2023-33930
9.1

This vulnerability allows attackers to upload malicious ZIP files containing dangerous file types to WordPress sites using the Unlimited Elements for ...

Jun 4, 2024
CVE-2023-25444
9.1

This vulnerability allows attackers to upload malicious files to WordPress sites using the JS Help Desk plugin. It affects all versions up to 2.7.7, p...

May 17, 2024
CVE-2024-34555
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Z-Downloads plugin. Attackers can upload malicious files ...

May 14, 2024
CVE-2024-34440
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the AI Engine: ChatGPT Chatbot plugin. Attackers can exploit ...

May 14, 2024
CVE-2024-32880
9.1

This vulnerability in pyload allows authenticated users to change the download folder and upload malicious templates, leading to remote code execution...

Apr 26, 2024
CVE-2024-32954
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Tribulant Newsletters plugin. Attackers can upload malici...

Apr 24, 2024
CVE-2024-32836
9.1

This vulnerability allows unauthenticated attackers to upload arbitrary files, including malicious scripts, to WordPress sites running the vulnerable ...

Apr 24, 2024
CVE-2024-31345
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Auto Poster plugin. Attackers can upload malicious files ...

Apr 7, 2024
CVE-2024-27951
9.1

This vulnerability allows attackers to upload malicious files, such as web shells, to WordPress servers running the vulnerable Multiple Page Generator...

Apr 3, 2024
CVE-2024-29100
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the AI Engine: ChatGPT Chatbot plugin. Attackers can exploit ...

Mar 28, 2024
CVE-2024-30231
9.1

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the vulnerable WebToffee Product Import Export for WooCommerc...

Mar 26, 2024
CVE-2024-26503
9.1

This vulnerability allows attackers to upload malicious files to the certbadge.php endpoint in Open eClass, potentially leading to remote code executi...

Mar 14, 2024
CVE-2023-6090
9.1

This vulnerability allows attackers to upload arbitrary files to WooCommerce sites using the Mollie Payments plugin, potentially leading to remote cod...

Feb 29, 2024
CVE-2024-22393
9.1

This vulnerability allows authenticated users to upload large image files that consume excessive server memory, potentially causing denial of service....

Feb 22, 2024
CVE-2023-40051
9.1

This vulnerability allows attackers to upload arbitrary files to Progress Application Server (PAS) for OpenEdge via the WEB transport. Affected organi...

Jan 18, 2024
CVE-2023-29102
9.1

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the Olive One Click Demo Import plugin. Attac...

Dec 20, 2023
CVE-2023-5965
9.1

This vulnerability allows authenticated privileged attackers to upload malicious zip files to EspoCRM servers, leading to arbitrary PHP code execution...

Nov 30, 2023
CVE-2023-42659
9.1

This vulnerability allows authenticated Ad Hoc Transfer users in WS_FTP Server to upload arbitrary files to any location on the underlying operating s...

Nov 7, 2023
CVE-2023-5185
9.1

Gym Management System Project v1.0 has an insecure file upload vulnerability that allows authenticated attackers to upload malicious files and execute...

Sep 28, 2023
CVE-2023-1721
9.1

Yoga Class Registration System 1.0 contains an unrestricted file upload vulnerability that allows authenticated administrators to upload malicious fil...

Jun 24, 2023
CVE-2023-28725
9.1

This vulnerability allows remote attackers to execute arbitrary Java code on General Bytes Crypto Application Server by uploading malicious applicatio...

Mar 22, 2023
CVE-2023-0587
9.1

An unauthenticated remote file upload vulnerability in Trend Micro Apex One allows attackers to upload arbitrary files to the server's SampleSubmissio...

Feb 1, 2023
CVE-2022-28700
9.1

This vulnerability allows authenticated WordPress users with appropriate permissions to create arbitrary files on the server via the GiveWP plugin's e...

Jul 21, 2022
CVE-2022-28223
9.1

This vulnerability allows authenticated admin users on Tekon KIO devices to escalate privileges to root by uploading malicious Lua plugin scripts. It ...

Mar 30, 2022
CVE-2022-24387
9.1

This vulnerability allows attackers with administrator or admin privileges in SmarterTrack to overwrite critical configuration files in the app_data/C...

Mar 14, 2022
CVE-2021-38484
9.1

This vulnerability allows attackers with administrator access to upload malicious files to InHand Networks IR615 routers without proper validation. Th...

Oct 19, 2021
CVE-2021-24220
9.1

This vulnerability in multiple Thrive Themes WordPress themes allows attackers to execute arbitrary code on affected websites. By exploiting an insecu...

Apr 12, 2021
CVE-2021-21014
9.1

This vulnerability allows authenticated attackers with admin console access to bypass file upload restrictions in Magento, potentially leading to arbi...

Feb 11, 2021
CVE-2020-24407
9.1

This CVE describes an unsafe file upload vulnerability in Magento that allows authenticated administrators to upload malicious files, potentially lead...

Nov 9, 2020
CVE-2020-24195
9.1

This vulnerability allows authenticated administrators in Online Bike Rental v1.0 to upload arbitrary files, including malicious scripts, leading to r...

Sep 9, 2020
CVE-2025-66074
9.0

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the WP Webhooks plugin, potentially leading to remote code exec...

Dec 18, 2025
CVE-2025-42910
9.0

This vulnerability allows authenticated attackers to upload arbitrary files, including malicious executables, to SAP Supplier Relationship Management ...

Oct 14, 2025
CVE-2025-54693
9.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Form Block plugin. At...

Aug 14, 2025
CVE-2024-51919
9.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the Fancy Product Designer plugin. Attackers ...

Jan 21, 2025
CVE-2024-39397
9.0

This vulnerability allows attackers to upload malicious files to Adobe Commerce servers, potentially leading to arbitrary code execution. It affects A...

Aug 14, 2024
CVE-2024-2636
9.0

CVE-2024-2636 is an unrestricted file upload vulnerability in Cegid Meta4 HR that allows attackers to upload malicious JSP files to the server via the...

Mar 19, 2024
CVE-2024-23630
9.0

This vulnerability allows authenticated attackers to upload arbitrary firmware to Motorola MR2600 routers, leading to remote code execution. Attackers...

Jan 26, 2024
CVE-2023-51412
9.0

CVE-2023-51412 is an unauthenticated arbitrary file upload vulnerability in the Piotnet Forms WordPress plugin. Attackers can upload malicious files w...

Dec 29, 2023

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,426 CVEs classified as CWE-434, with 703 rated critical and 608 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free