CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,471
Total CVEs
729
Critical
627
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 13
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Mingsoft 7

All Unrestricted File Upload CVEs (1,471)

CVE-2025-3054
8.8

The WP User Frontend Pro plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access or higher to upload...

Jun 5, 2025
CVE-2025-4800
8.8

The MasterStudy LMS Pro WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing fi...

May 28, 2025
CVE-2025-4317
8.8

The TheGem WordPress theme has an arbitrary file upload vulnerability in all versions up to 5.10.3. Authenticated attackers with Subscriber-level acce...

May 13, 2025
CVE-2025-4561
8.8

CVE-2025-4561 is an arbitrary file upload vulnerability in KFOX from KingFor that allows authenticated users with regular privileges to upload malicio...

May 12, 2025
CVE-2025-4279
8.8

The External Image Replace WordPress plugin allows authenticated attackers with contributor-level permissions or higher to upload arbitrary files due ...

May 5, 2025
CVE-2024-13418
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files through vulnerable plugins/th...

May 2, 2025
CVE-2025-3616
8.8

The Greenshift WordPress plugin versions 11.4 to 11.4.5 contain a vulnerability that allows authenticated users with Subscriber-level access or higher...

Apr 22, 2025
CVE-2025-29017
8.8

A remote code execution vulnerability in Code Astro Internet Banking System 2.0.0 allows attackers to upload malicious files through the profile_pic p...

Apr 10, 2025
CVE-2025-2525
8.8

The Streamit WordPress theme allows authenticated users with subscriber-level permissions or higher to upload arbitrary files due to missing file type...

Apr 8, 2025
CVE-2025-2780
8.8

The Woffice Core plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload arbitrary f...

Apr 4, 2025
CVE-2025-2891
8.8

The Real Estate 7 WordPress theme allows authenticated attackers with Seller-level access or higher to upload arbitrary files due to missing file type...

Apr 1, 2025
CVE-2025-2006
8.8

The Inline Image Upload for BBPress WordPress plugin allows authenticated attackers (Subscriber-level or higher) to upload arbitrary files due to miss...

Mar 29, 2025
CVE-2025-2249
8.8

The SoJ SoundSlides WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to missing f...

Mar 29, 2025
CVE-2024-9920
8.8

This vulnerability allows attackers to upload malicious files with dangerous extensions (.py, .sh, .bat, etc.) and execute them via the '/open_file' A...

Mar 20, 2025
CVE-2024-54525
8.8

This vulnerability allows attackers to modify protected system files by restoring maliciously crafted backup files. It affects Apple devices running v...

Mar 17, 2025
CVE-2024-13882
8.8

The Aiomatic WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to missing file typ...

Mar 8, 2025
CVE-2024-41339
8.8

This vulnerability allows attackers to upload malicious kernel modules through the CGI configuration upload endpoint in affected Draytek routers, lead...

Feb 27, 2025
CVE-2024-13714
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files due to missing file type vali...

Feb 12, 2025
CVE-2024-57668
8.8

Code-projects Shopping Portal v1.0 has an arbitrary file upload vulnerability in insert-product.php that allows attackers to upload malicious files to...

Feb 6, 2025
CVE-2025-0394
8.8

The Groundhogg WordPress plugin up to version 3.7.3.5 allows authenticated attackers with Author-level access or higher to upload arbitrary files due ...

Jan 14, 2025
CVE-2024-12854
8.8

The Garden Gnome Package WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missing f...

Jan 8, 2025
CVE-2024-12853
8.8

The Modula Image Gallery WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files via zip upload f...

Jan 8, 2025
CVE-2024-53345
8.8

An authenticated arbitrary file upload vulnerability in Car Rental Management System versions 1.0 through 1.3 allows attackers with valid credentials ...

Jan 7, 2025
CVE-2024-12700
8.8

CVE-2024-12700 is an unrestricted file upload vulnerability in Aggregate Digital software that allows authenticated low-privileged users to upload JSP...

Dec 19, 2024
CVE-2024-11984
8.8

This vulnerability allows authenticated remote attackers to upload malicious ZIP files through the epaper draft function in Corporate Training Managem...

Dec 19, 2024
CVE-2024-10590
8.8

The Opt-In Downloads WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files due to missing f...

Dec 12, 2024
CVE-2024-10578
8.8

The Pubnews WordPress theme has a vulnerability that allows authenticated attackers with Subscriber-level access or higher to install arbitrary plugin...

Dec 6, 2024
CVE-2024-46625
8.8

This vulnerability allows authenticated attackers to upload malicious SVG files to the /documentCache/upload endpoint in InfoDom Performa 365 v4.0.1, ...

Dec 3, 2024
CVE-2024-9660
8.8

This vulnerability allows authenticated attackers with Student-level access or higher to upload arbitrary files to WordPress sites running the School ...

Nov 23, 2024
CVE-2024-51364
8.8

An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to upload malicious .xml files that can lead to remote code execution. ...

Nov 21, 2024
CVE-2024-51743
8.8

This vulnerability allows authenticated instructors in MarkUs to write arbitrary files to any location on the web server, potentially leading to remot...

Nov 18, 2024
CVE-2024-45263
8.8

This vulnerability allows attackers to upload arbitrary files to affected GL-iNet router devices via the upload interface. Once uploaded, these files ...

Oct 24, 2024
CVE-2024-10201
8.8

This vulnerability in the Wellchoose Administrative Management System allows authenticated users with regular privileges to upload malicious files due...

Oct 21, 2024
CVE-2024-37869
8.8

This CVE describes a file upload vulnerability in Itsourcecode Online Discussion Forum Project v1.0 that allows remote attackers to upload malicious f...

Oct 4, 2024
CVE-2024-46441
8.8

This vulnerability allows attackers to upload arbitrary files, including malicious PHP scripts, to YPay 1.2.0 payment software. Attackers can achieve ...

Sep 27, 2024
CVE-2024-46373
8.8

Dedecms V5.7.115 contains a file upload vulnerability in the backend that allows authenticated attackers to upload malicious files and execute arbitra...

Sep 18, 2024
CVE-2024-7770
8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files due to missing file type vali...

Sep 10, 2024
CVE-2024-45171
8.8

CVE-2024-45171 is an unrestricted file upload vulnerability in za-internet C-MOR Video Surveillance 5.2401 that allows authenticated users to upload a...

Sep 5, 2024
CVE-2024-42779
8.8

An unrestricted file upload vulnerability in Kashipara Music Management System v1.0 allows attackers to upload malicious PHP files via the /music/ajax...

Aug 21, 2024
CVE-2024-42676
8.8

This vulnerability allows remote attackers to upload arbitrary files to the Huizhi enterprise resource management system, potentially leading to remot...

Aug 15, 2024
CVE-2024-6823
8.8

The Media Library Assistant WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missin...

Aug 13, 2024
CVE-2024-41913
8.8

This vulnerability in Poly Clariti Manager devices allows attackers to execute arbitrary code by exploiting improper input sanitization. It affects or...

Aug 6, 2024
CVE-2024-40645
8.8

This vulnerability allows authenticated users in FOG Project to upload malicious files disguised as images, leading to remote code execution on the se...

Jul 31, 2024
CVE-2024-6756
8.8

The Social Auto Poster WordPress plugin allows authenticated users with Contributor-level permissions or higher to upload arbitrary files due to missi...

Jul 24, 2024
CVE-2024-40400
8.8

This vulnerability allows attackers to upload malicious files through Automad's image upload function, potentially leading to remote code execution. A...

Jul 19, 2024
CVE-2024-3242
8.8

The Brizy Page Builder WordPress plugin allows authenticated attackers with contributor-level access or higher to upload arbitrary files due to insuff...

Jul 18, 2024
CVE-2024-31411
8.8

Authenticated users in Apache StreamPipes can upload dangerous file types like executables, potentially leading to remote code execution. This affects...

Jul 17, 2024
CVE-2024-5080
8.8

This vulnerability in the wp-eMember WordPress plugin allows administrators to upload arbitrary files without validation, including malicious PHP file...

Jul 13, 2024
CVE-2024-40545
8.8

This vulnerability allows attackers to upload malicious files to the PublicCMS administration interface, leading to remote code execution. It affects ...

Jul 12, 2024
CVE-2024-40548
8.8

This vulnerability allows attackers to upload malicious files to the PublicCMS admin interface, leading to remote code execution. Any organization run...

Jul 12, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,471 CVEs classified as CWE-434, with 729 rated critical and 627 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free