CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,475
Total CVEs
732
Critical
628
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 13
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Mingsoft 7

All Unrestricted File Upload CVEs (1,475)

CVE-2024-5080
8.8

This vulnerability in the wp-eMember WordPress plugin allows administrators to upload arbitrary files without validation, including malicious PHP file...

Jul 13, 2024
CVE-2024-40545
8.8

This vulnerability allows attackers to upload malicious files to the PublicCMS administration interface, leading to remote code execution. It affects ...

Jul 12, 2024
CVE-2024-40548
8.8

This vulnerability allows attackers to upload malicious files to the PublicCMS admin interface, leading to remote code execution. Any organization run...

Jul 12, 2024
CVE-2024-40550
8.8

This vulnerability allows attackers to upload arbitrary files to the Public CMS admin interface, which can lead to remote code execution. It affects P...

Jul 12, 2024
CVE-2024-5441
8.8

The Modern Events Calendar WordPress plugin allows arbitrary file uploads due to missing file type validation in the set_featured_image function. This...

Jul 9, 2024
CVE-2024-6319
8.8

The IMGspider WordPress plugin allows authenticated attackers with contributor-level permissions or higher to upload arbitrary files due to missing fi...

Jul 4, 2024
CVE-2024-6054
8.8

The Auto Featured Image WordPress plugin allows authenticated users with contributor-level permissions or higher to upload arbitrary files due to miss...

Jun 27, 2024
CVE-2024-2381
8.8

The AliExpress Dropshipping with AliNext Lite WordPress plugin allows authenticated attackers with subscriber-level access or higher to upload arbitra...

Jun 19, 2024
CVE-2024-36396
8.8

This vulnerability in Verint software allows attackers to upload dangerous file types without proper restrictions, potentially leading to remote code ...

Jun 13, 2024
CVE-2022-45171
8.8

This vulnerability allows authenticated remote users to upload dangerous file types without restrictions in LIVEBOX Collaboration vDesk's vShare web s...

May 28, 2024
CVE-2024-5247
8.8

This vulnerability allows authenticated remote attackers to upload arbitrary files to NETGEAR ProSAFE Network Management System installations, leading...

May 23, 2024
CVE-2024-4397
8.8

The LearnPress WordPress LMS plugin has a vulnerability that allows authenticated attackers with Instructor-level permissions or higher to upload arbi...

May 14, 2024
CVE-2021-35002
8.8

This vulnerability allows authenticated remote attackers to upload malicious files through email attachments in BMC Track-It!, leading to remote code ...

May 7, 2024
CVE-2023-38098
8.8

This vulnerability allows authenticated remote attackers to bypass authentication and upload arbitrary files to NETGEAR ProSAFE Network Management Sys...

May 3, 2024
CVE-2023-38095
8.8

This vulnerability allows authenticated remote attackers to bypass authentication and upload arbitrary files to NETGEAR ProSAFE Network Management Sys...

May 3, 2024
CVE-2024-23534
8.8

This vulnerability allows authenticated remote attackers to upload malicious files to Ivanti Avalanche web components, leading to arbitrary command ex...

Apr 19, 2024
CVE-2024-29387
8.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of projeqtor. Attackers can exploit the /v...

Apr 4, 2024
CVE-2024-29514
8.8

This vulnerability allows authenticated remote attackers to upload malicious PHP files to lepton v7.1.0, potentially leading to remote code execution....

Apr 2, 2024
CVE-2024-27964
8.8

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Zippy plugin, potentially leading to remote code executio...

Mar 21, 2024
CVE-2024-1205
8.8

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to upload arbitrary files to the server due to missing ...

Mar 20, 2024
CVE-2024-1311
8.8

The Brizy Page Builder WordPress plugin allows authenticated attackers with contributor-level access or higher to upload arbitrary files due to missin...

Mar 13, 2024
CVE-2024-1986
8.8

The Booster Elite for WooCommerce WordPress plugin allows arbitrary file uploads due to missing file type validation in the wc_add_new_product() funct...

Mar 7, 2024
CVE-2024-1468
8.8

The Avada WordPress theme has a vulnerability that allows authenticated attackers with contributor-level access or higher to upload arbitrary files du...

Feb 29, 2024
CVE-2024-25832
8.8

F-logic DataCube3 v1.0 has an unrestricted file upload vulnerability that allows authenticated attackers to upload malicious files by manipulating fil...

Feb 29, 2024
CVE-2024-25869
8.8

An unrestricted file upload vulnerability in CodeAstro Membership Management System v1.0 allows remote attackers to upload malicious PHP files through...

Feb 28, 2024
CVE-2024-23811
8.8

SINEC NMS versions before V2.0 SP1 contain a vulnerability allowing arbitrary file upload via TFTP. Attackers can upload malicious firmware images or ...

Feb 13, 2024
CVE-2023-40265
8.8

This vulnerability allows authenticated attackers to upload malicious files to Atos Unify OpenScape Xpressions WebAssistant, leading to remote code ex...

Feb 8, 2024
CVE-2024-24350
8.8

An authenticated file upload vulnerability in Software Publico e-Sic Livre v2.0 and earlier allows remote attackers to bypass extension filtering and ...

Feb 8, 2024
CVE-2024-22567
8.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to MCMS 5.3.5 systems via a crafted POST request to /ms/file/upload.do. ...

Feb 5, 2024
CVE-2024-23180
8.8

This vulnerability allows authenticated attackers to upload specially crafted SVG files that bypass input validation in a-blog CMS, leading to remote ...

Jan 23, 2024
CVE-2024-22895
8.8

DedeCMS 5.7.112 contains an unrestricted file upload vulnerability in the module_upload.php component. Attackers can upload malicious files to execute...

Jan 22, 2024
CVE-2023-4536
8.8

This vulnerability in the My Account Page Editor WordPress plugin allows authenticated users (even with low privileges like 'subscriber') to upload ar...

Jan 16, 2024
CVE-2023-6140
8.8

The Essential Real Estate WordPress plugin before version 4.4.0 allows low-privileged users like subscribers to upload malicious PHP files disguised a...

Jan 8, 2024
CVE-2023-50760
8.8

Online Notice Board System v1.0 has an insecure file upload vulnerability that allows authenticated attackers to upload malicious files. This can lead...

Jan 4, 2024
CVE-2023-50038
8.8

CVE-2023-50038 is an arbitrary file upload vulnerability in Textpattern CMS v4.8.8 that allows authenticated attackers to upload malicious files to th...

Dec 28, 2023
CVE-2023-50692
8.8

This vulnerability allows remote attackers to upload malicious files to JIZHICMS v2.5 through the download_url parameter, potentially leading to arbit...

Dec 28, 2023
CVE-2023-5931
8.8

The rtMedia WordPress plugin before version 4.6.16 has an unrestricted file upload vulnerability that allows authenticated users with low privileges (...

Dec 26, 2023
CVE-2023-5673
8.8

The WP Mail Log WordPress plugin before version 1.1.3 fails to properly validate file extensions when uploading attachments to emails, allowing attack...

Dec 26, 2023
CVE-2023-6976
8.8

This vulnerability in MLflow allows attackers to write arbitrary files to arbitrary locations on the server filesystem, potentially leading to remote ...

Dec 20, 2023
CVE-2023-4311
8.8

The Vrm 360 3D Model Viewer WordPress plugin through version 1.2.1 contains an arbitrary file upload vulnerability due to insufficient security checks...

Dec 18, 2023
CVE-2023-48394
8.8

Kaifa Technology WebITR online attendance system has an unrestricted file upload vulnerability that allows authenticated users to upload dangerous fil...

Dec 15, 2023
CVE-2023-50564
8.8

This vulnerability allows attackers to upload arbitrary ZIP files containing malicious code to Pluck-CMS, leading to remote code execution. Attackers ...

Dec 14, 2023
CVE-2023-48965
8.8

This vulnerability in ThinkAdmin v6.1.53 allows attackers to upload and execute arbitrary PHP files via a crafted URL to the /admin/api.plugs/script e...

Dec 4, 2023
CVE-2023-49052
8.8

This vulnerability allows remote attackers to upload malicious files through Microweber's forms component, leading to arbitrary code execution. It aff...

Nov 30, 2023
CVE-2023-4225
8.8

This vulnerability allows authenticated users with learner roles in Chamilo LMS to upload arbitrary PHP files through the exercise.ajax.php endpoint, ...

Nov 28, 2023
CVE-2023-4223
8.8

This vulnerability allows authenticated users with learner roles in Chamilo LMS to upload arbitrary PHP files through the document upload functionalit...

Nov 28, 2023
CVE-2023-39548
8.8

This vulnerability allows an attacker who can log into affected NEC clustering software to execute arbitrary commands with potentially elevated privil...

Nov 17, 2023
CVE-2023-47621
8.8

Guest Entries PHP library versions before 3.1.2 allow authenticated users to upload PHP files through the front-end file upload feature, potentially l...

Nov 13, 2023
CVE-2023-41357
8.8

CVE-2023-41357 is an unrestricted file upload vulnerability in Galaxy Software Services Corporation Vitals ESP knowledge base management portal. Authe...

Nov 3, 2023
CVE-2023-46428
8.8

An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to upload malicious files that can lead to remote code execution. This affe...

Nov 1, 2023

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,475 CVEs classified as CWE-434, with 732 rated critical and 628 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free