CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,467
Total CVEs
727
Critical
625
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Ivanti 13
3 Zohocorp 13
4 Phpgurukul 8
5 Dedecms 7
6 Mingsoft 7
7 Apache 7
8 Netgear 7
9 Oretnom23 7
10 Sap 7

All Unrestricted File Upload CVEs (1,467)

CVE-2021-47758
8.8

CVE-2021-47758 allows authenticated attackers to upload malicious PHP plugins through Chikitsa Patient Management System's module upload functionality...

Jan 15, 2026
CVE-2025-13062
8.8

The Supreme Modules Lite WordPress plugin has an arbitrary file upload vulnerability in versions up to 2.5.62. Authenticated attackers with author-lev...

Jan 15, 2026
CVE-2022-50936
8.8

This vulnerability allows authenticated attackers to execute arbitrary PHP code on WBCE CMS servers by uploading malicious droplets through the admin ...

Jan 13, 2026
CVE-2025-46068
8.8

This vulnerability allows remote attackers to execute arbitrary code on Automai Director v25.2.0 systems by exploiting the update mechanism. Attackers...

Jan 12, 2026
CVE-2025-15158
8.8

The WP Enable WebP WordPress plugin has a vulnerability that allows authenticated attackers with Author-level permissions or higher to upload arbitrar...

Jan 7, 2026
CVE-2025-15240
8.8

CVE-2025-15240 is an arbitrary file upload vulnerability in QOCA aim AI Medical Cloud Platform that allows authenticated attackers to upload malicious...

Jan 5, 2026
CVE-2025-55061
8.8

CVE-2025-55061 is an unrestricted file upload vulnerability (CWE-434) that allows attackers to upload malicious files to vulnerable systems. This coul...

Dec 29, 2025
CVE-2025-2155
8.8

This vulnerability allows attackers to upload malicious files to Specto CM systems, potentially leading to remote code execution. It affects all Spect...

Dec 24, 2025
CVE-2023-53971
8.8

WebTareas 2.4 contains an authenticated file upload vulnerability that allows attackers to upload malicious PHP files and execute arbitrary code on th...

Dec 22, 2025
CVE-2025-14849
8.8

Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, allowing attackers to upload malicious files to the server. This can lead to remo...

Dec 18, 2025
CVE-2023-53942
8.8

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives. Attackers ca...

Dec 18, 2025
CVE-2023-53933
8.8

CVE-2023-53933 is a remote code execution vulnerability in Serendipity 2.4.0 that allows authenticated attackers to upload malicious PHP files with .p...

Dec 17, 2025
CVE-2023-53924
8.8

This vulnerability allows authenticated attackers to upload malicious PHP files disguised as avatar images in UliCMS, leading to remote code execution...

Dec 17, 2025
CVE-2023-53868
8.8

CVE-2023-53868 is a remote code execution vulnerability in Coppermine Gallery that allows authenticated attackers to upload malicious PHP files throug...

Dec 15, 2025
CVE-2024-44598
8.8

FNT Command 13.4.0 contains a vulnerability in its C Base Module that allows remote code execution. Attackers can upload malicious files to execute ar...

Dec 15, 2025
CVE-2025-13094
8.8

The WP3D Model Import Viewer plugin for WordPress has a vulnerability that allows authenticated attackers with Author-level access or higher to upload...

Dec 13, 2025
CVE-2025-12968
8.8

The Infility Global WordPress plugin allows authenticated attackers with subscriber-level access or higher to upload arbitrary files due to missing fi...

Dec 12, 2025
CVE-2025-34506
8.8

This vulnerability allows authenticated administrators in WBCE CMS to upload malicious ZIP modules containing PHP reverse shell code, leading to remot...

Dec 11, 2025
CVE-2024-58283
8.8

This vulnerability allows authenticated attackers to upload malicious PHP files through the Elfinder file manager in WBCE CMS version 1.6.2, leading t...

Dec 10, 2025
CVE-2024-58279
8.8

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through...

Dec 10, 2025
CVE-2024-58281
8.8

Dotclear 2.29 contains an authenticated remote code execution vulnerability where attackers with valid credentials can upload malicious PHP files thro...

Dec 10, 2025
CVE-2025-14390
8.8

This CSRF vulnerability in the Video Merchant WordPress plugin allows unauthenticated attackers to upload arbitrary files by tricking administrators i...

Dec 10, 2025
CVE-2025-56704
8.8

LeptonCMS 7.3.0 contains an arbitrary file upload vulnerability due to insufficient file validation. Authenticated attackers can upload malicious ZIP/...

Dec 9, 2025
CVE-2025-13066
8.8

The Demo Importer Plus WordPress plugin allows authenticated attackers with author-level access or higher to upload arbitrary files due to insufficien...

Dec 5, 2025
CVE-2025-13543
8.8

The PostGallery WordPress plugin has a vulnerability that allows authenticated users with subscriber-level permissions or higher to upload arbitrary f...

Dec 4, 2025
CVE-2025-13536
8.8

The Blubrry PowerPress WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to insuff...

Nov 27, 2025
CVE-2025-13156
8.8

The Vitepos WordPress plugin allows authenticated users with subscriber-level access or higher to upload arbitrary files due to missing file type vali...

Nov 21, 2025
CVE-2025-12138
8.8

The URL Image Importer WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files, including PHP fil...

Nov 21, 2025
CVE-2025-13069
8.8

The Enable SVG, WebP, and ICO Upload WordPress plugin allows authenticated attackers with author-level access or higher to upload arbitrary files due ...

Nov 18, 2025
CVE-2025-12775
8.8

The WP Dropzone WordPress plugin allows authenticated users with subscriber-level access or higher to upload arbitrary files to the server due to insu...

Nov 18, 2025
CVE-2025-63748
8.8

QaTraq 6.9.2 contains an unrestricted file upload vulnerability that allows authenticated users to upload PHP files, leading to remote code execution....

Nov 17, 2025
CVE-2025-12846
8.8

The Blocksy Companion WordPress plugin allows authenticated users with author privileges or higher to upload arbitrary files due to insufficient SVG f...

Nov 11, 2025
CVE-2025-12161
8.8

The Smart Auto Upload Images WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to ...

Nov 8, 2025
CVE-2025-11724
8.8

The EM Beer Manager WordPress plugin allows authenticated attackers with subscriber-level access or higher to upload arbitrary files, including PHP fi...

Nov 4, 2025
CVE-2020-36863
8.8

This vulnerability allows authenticated attackers to upload PHP files to Nagios XI's Audio Import directory and execute them, leading to remote code e...

Oct 30, 2025
CVE-2025-9561
8.8

The AP Background WordPress plugin versions 3.8.1 to 3.8.2 contain an arbitrary file upload vulnerability due to missing authorization and insufficien...

Oct 3, 2025
CVE-2025-10647
8.8

The Embed PDF for WPForms WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing ...

Sep 19, 2025
CVE-2025-9216
8.8

The StoreEngine WordPress plugin up to version 1.5.0 has an arbitrary file upload vulnerability in its import function. Authenticated attackers with S...

Sep 17, 2025
CVE-2025-56263
8.8

CVE-2025-56263 is an arbitrary file upload vulnerability in by-night sms V1.0 that allows attackers to upload any file type and size via the /api/sms/...

Sep 16, 2025
CVE-2025-9712
8.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager systems by exploiting insufficient fil...

Sep 9, 2025
CVE-2025-7847
8.8

The AI Engine WordPress plugin versions 2.9.3 and 2.9.4 contain an arbitrary file upload vulnerability in the REST API endpoint. This allows authentic...

Jul 31, 2025
CVE-2025-8323
8.8

CVE-2025-8323 is an arbitrary file upload vulnerability in e-School from Ventem that allows unauthenticated remote attackers to upload malicious files...

Jul 30, 2025
CVE-2025-5831
8.8

The Droip WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files due to missing file type va...

Jul 25, 2025
CVE-2025-46384
8.8

CVE-2025-46384 is an unrestricted file upload vulnerability (CWE-434) that allows attackers to upload malicious files to vulnerable systems. This coul...

Jul 20, 2025
CVE-2025-4413
8.8

The Pixabay Images WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missing file ty...

Jun 18, 2025
CVE-2025-5395
8.8

The WordPress Automatic Plugin has a vulnerability allowing authenticated attackers with Author-level access or higher to upload arbitrary files due t...

Jun 11, 2025
CVE-2025-4954
8.8

The Axle Demo Importer WordPress plugin through version 1.0.3 contains an arbitrary file upload vulnerability that allows authenticated users with aut...

Jun 10, 2025
CVE-2025-4387
8.8

The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability that allows attackers with subscriber-leve...

Jun 10, 2025
CVE-2025-3054
8.8

The WP User Frontend Pro plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access or higher to upload...

Jun 5, 2025
CVE-2025-4800
8.8

The MasterStudy LMS Pro WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing fi...

May 28, 2025

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,467 CVEs classified as CWE-434, with 727 rated critical and 625 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free