CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,471)
The WP User Frontend Pro plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access or higher to upload...
Jun 5, 2025The MasterStudy LMS Pro WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing fi...
May 28, 2025The TheGem WordPress theme has an arbitrary file upload vulnerability in all versions up to 5.10.3. Authenticated attackers with Subscriber-level acce...
May 13, 2025CVE-2025-4561 is an arbitrary file upload vulnerability in KFOX from KingFor that allows authenticated users with regular privileges to upload malicio...
May 12, 2025The External Image Replace WordPress plugin allows authenticated attackers with contributor-level permissions or higher to upload arbitrary files due ...
May 5, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files through vulnerable plugins/th...
May 2, 2025The Greenshift WordPress plugin versions 11.4 to 11.4.5 contain a vulnerability that allows authenticated users with Subscriber-level access or higher...
Apr 22, 2025A remote code execution vulnerability in Code Astro Internet Banking System 2.0.0 allows attackers to upload malicious files through the profile_pic p...
Apr 10, 2025The Streamit WordPress theme allows authenticated users with subscriber-level permissions or higher to upload arbitrary files due to missing file type...
Apr 8, 2025The Woffice Core plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload arbitrary f...
Apr 4, 2025The Real Estate 7 WordPress theme allows authenticated attackers with Seller-level access or higher to upload arbitrary files due to missing file type...
Apr 1, 2025The Inline Image Upload for BBPress WordPress plugin allows authenticated attackers (Subscriber-level or higher) to upload arbitrary files due to miss...
Mar 29, 2025The SoJ SoundSlides WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to missing f...
Mar 29, 2025This vulnerability allows attackers to upload malicious files with dangerous extensions (.py, .sh, .bat, etc.) and execute them via the '/open_file' A...
Mar 20, 2025This vulnerability allows attackers to modify protected system files by restoring maliciously crafted backup files. It affects Apple devices running v...
Mar 17, 2025The Aiomatic WordPress plugin allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due to missing file typ...
Mar 8, 2025This vulnerability allows attackers to upload malicious kernel modules through the CGI configuration upload endpoint in affected Draytek routers, lead...
Feb 27, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files due to missing file type vali...
Feb 12, 2025Code-projects Shopping Portal v1.0 has an arbitrary file upload vulnerability in insert-product.php that allows attackers to upload malicious files to...
Feb 6, 2025The Groundhogg WordPress plugin up to version 3.7.3.5 allows authenticated attackers with Author-level access or higher to upload arbitrary files due ...
Jan 14, 2025The Garden Gnome Package WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missing f...
Jan 8, 2025The Modula Image Gallery WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files via zip upload f...
Jan 8, 2025An authenticated arbitrary file upload vulnerability in Car Rental Management System versions 1.0 through 1.3 allows attackers with valid credentials ...
Jan 7, 2025CVE-2024-12700 is an unrestricted file upload vulnerability in Aggregate Digital software that allows authenticated low-privileged users to upload JSP...
Dec 19, 2024This vulnerability allows authenticated remote attackers to upload malicious ZIP files through the epaper draft function in Corporate Training Managem...
Dec 19, 2024The Opt-In Downloads WordPress plugin allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files due to missing f...
Dec 12, 2024The Pubnews WordPress theme has a vulnerability that allows authenticated attackers with Subscriber-level access or higher to install arbitrary plugin...
Dec 6, 2024This vulnerability allows authenticated attackers to upload malicious SVG files to the /documentCache/upload endpoint in InfoDom Performa 365 v4.0.1, ...
Dec 3, 2024This vulnerability allows authenticated attackers with Student-level access or higher to upload arbitrary files to WordPress sites running the School ...
Nov 23, 2024An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to upload malicious .xml files that can lead to remote code execution. ...
Nov 21, 2024This vulnerability allows authenticated instructors in MarkUs to write arbitrary files to any location on the web server, potentially leading to remot...
Nov 18, 2024This vulnerability allows attackers to upload arbitrary files to affected GL-iNet router devices via the upload interface. Once uploaded, these files ...
Oct 24, 2024This vulnerability in the Wellchoose Administrative Management System allows authenticated users with regular privileges to upload malicious files due...
Oct 21, 2024This CVE describes a file upload vulnerability in Itsourcecode Online Discussion Forum Project v1.0 that allows remote attackers to upload malicious f...
Oct 4, 2024This vulnerability allows attackers to upload arbitrary files, including malicious PHP scripts, to YPay 1.2.0 payment software. Attackers can achieve ...
Sep 27, 2024Dedecms V5.7.115 contains a file upload vulnerability in the backend that allows authenticated attackers to upload malicious files and execute arbitra...
Sep 18, 2024This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files due to missing file type vali...
Sep 10, 2024CVE-2024-45171 is an unrestricted file upload vulnerability in za-internet C-MOR Video Surveillance 5.2401 that allows authenticated users to upload a...
Sep 5, 2024An unrestricted file upload vulnerability in Kashipara Music Management System v1.0 allows attackers to upload malicious PHP files via the /music/ajax...
Aug 21, 2024This vulnerability allows remote attackers to upload arbitrary files to the Huizhi enterprise resource management system, potentially leading to remot...
Aug 15, 2024The Media Library Assistant WordPress plugin allows authenticated attackers with Author-level access or higher to upload arbitrary files due to missin...
Aug 13, 2024This vulnerability in Poly Clariti Manager devices allows attackers to execute arbitrary code by exploiting improper input sanitization. It affects or...
Aug 6, 2024This vulnerability allows authenticated users in FOG Project to upload malicious files disguised as images, leading to remote code execution on the se...
Jul 31, 2024The Social Auto Poster WordPress plugin allows authenticated users with Contributor-level permissions or higher to upload arbitrary files due to missi...
Jul 24, 2024This vulnerability allows attackers to upload malicious files through Automad's image upload function, potentially leading to remote code execution. A...
Jul 19, 2024The Brizy Page Builder WordPress plugin allows authenticated attackers with contributor-level access or higher to upload arbitrary files due to insuff...
Jul 18, 2024Authenticated users in Apache StreamPipes can upload dangerous file types like executables, potentially leading to remote code execution. This affects...
Jul 17, 2024This vulnerability in the wp-eMember WordPress plugin allows administrators to upload arbitrary files without validation, including malicious PHP file...
Jul 13, 2024This vulnerability allows attackers to upload malicious files to the PublicCMS administration interface, leading to remote code execution. It affects ...
Jul 12, 2024This vulnerability allows attackers to upload malicious files to the PublicCMS admin interface, leading to remote code execution. Any organization run...
Jul 12, 2024About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,471 CVEs classified as CWE-434, with 729 rated critical and 627 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free