CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,467)
CVE-2021-47758 allows authenticated attackers to upload malicious PHP plugins through Chikitsa Patient Management System's module upload functionality...
Jan 15, 2026The Supreme Modules Lite WordPress plugin has an arbitrary file upload vulnerability in versions up to 2.5.62. Authenticated attackers with author-lev...
Jan 15, 2026This vulnerability allows authenticated attackers to execute arbitrary PHP code on WBCE CMS servers by uploading malicious droplets through the admin ...
Jan 13, 2026This vulnerability allows remote attackers to execute arbitrary code on Automai Director v25.2.0 systems by exploiting the update mechanism. Attackers...
Jan 12, 2026The WP Enable WebP WordPress plugin has a vulnerability that allows authenticated attackers with Author-level permissions or higher to upload arbitrar...
Jan 7, 2026CVE-2025-15240 is an arbitrary file upload vulnerability in QOCA aim AI Medical Cloud Platform that allows authenticated attackers to upload malicious...
Jan 5, 2026CVE-2025-55061 is an unrestricted file upload vulnerability (CWE-434) that allows attackers to upload malicious files to vulnerable systems. This coul...
Dec 29, 2025This vulnerability allows attackers to upload malicious files to Specto CM systems, potentially leading to remote code execution. It affects all Spect...
Dec 24, 2025WebTareas 2.4 contains an authenticated file upload vulnerability that allows attackers to upload malicious PHP files and execute arbitrary code on th...
Dec 22, 2025Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, allowing attackers to upload malicious files to the server. This can lead to remo...
Dec 18, 2025File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives. Attackers ca...
Dec 18, 2025CVE-2023-53933 is a remote code execution vulnerability in Serendipity 2.4.0 that allows authenticated attackers to upload malicious PHP files with .p...
Dec 17, 2025This vulnerability allows authenticated attackers to upload malicious PHP files disguised as avatar images in UliCMS, leading to remote code execution...
Dec 17, 2025CVE-2023-53868 is a remote code execution vulnerability in Coppermine Gallery that allows authenticated attackers to upload malicious PHP files throug...
Dec 15, 2025FNT Command 13.4.0 contains a vulnerability in its C Base Module that allows remote code execution. Attackers can upload malicious files to execute ar...
Dec 15, 2025The WP3D Model Import Viewer plugin for WordPress has a vulnerability that allows authenticated attackers with Author-level access or higher to upload...
Dec 13, 2025The Infility Global WordPress plugin allows authenticated attackers with subscriber-level access or higher to upload arbitrary files due to missing fi...
Dec 12, 2025This vulnerability allows authenticated administrators in WBCE CMS to upload malicious ZIP modules containing PHP reverse shell code, leading to remot...
Dec 11, 2025This vulnerability allows authenticated attackers to upload malicious PHP files through the Elfinder file manager in WBCE CMS version 1.6.2, leading t...
Dec 10, 2025appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through...
Dec 10, 2025Dotclear 2.29 contains an authenticated remote code execution vulnerability where attackers with valid credentials can upload malicious PHP files thro...
Dec 10, 2025This CSRF vulnerability in the Video Merchant WordPress plugin allows unauthenticated attackers to upload arbitrary files by tricking administrators i...
Dec 10, 2025LeptonCMS 7.3.0 contains an arbitrary file upload vulnerability due to insufficient file validation. Authenticated attackers can upload malicious ZIP/...
Dec 9, 2025The Demo Importer Plus WordPress plugin allows authenticated attackers with author-level access or higher to upload arbitrary files due to insufficien...
Dec 5, 2025The PostGallery WordPress plugin has a vulnerability that allows authenticated users with subscriber-level permissions or higher to upload arbitrary f...
Dec 4, 2025The Blubrry PowerPress WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to insuff...
Nov 27, 2025The Vitepos WordPress plugin allows authenticated users with subscriber-level access or higher to upload arbitrary files due to missing file type vali...
Nov 21, 2025The URL Image Importer WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files, including PHP fil...
Nov 21, 2025The Enable SVG, WebP, and ICO Upload WordPress plugin allows authenticated attackers with author-level access or higher to upload arbitrary files due ...
Nov 18, 2025The WP Dropzone WordPress plugin allows authenticated users with subscriber-level access or higher to upload arbitrary files to the server due to insu...
Nov 18, 2025QaTraq 6.9.2 contains an unrestricted file upload vulnerability that allows authenticated users to upload PHP files, leading to remote code execution....
Nov 17, 2025The Blocksy Companion WordPress plugin allows authenticated users with author privileges or higher to upload arbitrary files due to insufficient SVG f...
Nov 11, 2025The Smart Auto Upload Images WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to ...
Nov 8, 2025The EM Beer Manager WordPress plugin allows authenticated attackers with subscriber-level access or higher to upload arbitrary files, including PHP fi...
Nov 4, 2025This vulnerability allows authenticated attackers to upload PHP files to Nagios XI's Audio Import directory and execute them, leading to remote code e...
Oct 30, 2025The AP Background WordPress plugin versions 3.8.1 to 3.8.2 contain an arbitrary file upload vulnerability due to missing authorization and insufficien...
Oct 3, 2025The Embed PDF for WPForms WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing ...
Sep 19, 2025The StoreEngine WordPress plugin up to version 1.5.0 has an arbitrary file upload vulnerability in its import function. Authenticated attackers with S...
Sep 17, 2025CVE-2025-56263 is an arbitrary file upload vulnerability in by-night sms V1.0 that allows attackers to upload any file type and size via the /api/sms/...
Sep 16, 2025This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager systems by exploiting insufficient fil...
Sep 9, 2025The AI Engine WordPress plugin versions 2.9.3 and 2.9.4 contain an arbitrary file upload vulnerability in the REST API endpoint. This allows authentic...
Jul 31, 2025CVE-2025-8323 is an arbitrary file upload vulnerability in e-School from Ventem that allows unauthenticated remote attackers to upload malicious files...
Jul 30, 2025The Droip WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files due to missing file type va...
Jul 25, 2025CVE-2025-46384 is an unrestricted file upload vulnerability (CWE-434) that allows attackers to upload malicious files to vulnerable systems. This coul...
Jul 20, 2025The Pixabay Images WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missing file ty...
Jun 18, 2025The WordPress Automatic Plugin has a vulnerability allowing authenticated attackers with Author-level access or higher to upload arbitrary files due t...
Jun 11, 2025The Axle Demo Importer WordPress plugin through version 1.0.3 contains an arbitrary file upload vulnerability that allows authenticated users with aut...
Jun 10, 2025The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability that allows attackers with subscriber-leve...
Jun 10, 2025The WP User Frontend Pro plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access or higher to upload...
Jun 5, 2025The MasterStudy LMS Pro WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing fi...
May 28, 2025About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,467 CVEs classified as CWE-434, with 727 rated critical and 625 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free