CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,476)
An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to upload malicious files that can lead to remote code execution. This affe...
Nov 1, 2023SugarCRM has an unrestricted file upload vulnerability in the Notes module that allows authenticated users to upload malicious PHP files. This affects...
Oct 27, 2023This vulnerability allows authenticated attackers to upload arbitrary files and execute code on the underlying operating system through the Unify Open...
Oct 9, 2023This vulnerability allows remote attackers to upload malicious files through the edit profile component in Simple and Nice Shopping Cart Script v1.0, ...
Oct 6, 2023This CVE describes an authenticated command injection vulnerability in Digital China Networks DCFW-1800-SDC firewall devices. An attacker with valid c...
Oct 4, 2023This vulnerability allows authenticated attackers to upload arbitrary files to the affected application, potentially leading to remote code execution ...
Oct 3, 2023This vulnerability allows remote attackers to execute arbitrary code on Economizzer servers by uploading malicious PHP files as attachments. Attackers...
Sep 28, 2023This vulnerability in EliteCMS v1.01 allows remote attackers to upload arbitrary files through the manage_uploads.php component, potentially leading t...
Sep 20, 2023An unrestricted file upload vulnerability in Fl3xx Dispatch and Crew versions 2.10.37 allows remote attackers to upload malicious files via the add at...
Sep 20, 2023CVE-2023-36319 is a file upload vulnerability in Openupload Stable v0.4.3 that allows remote attackers to execute arbitrary code via the compress-inc....
Sep 20, 2023This vulnerability allows attackers to upload malicious JPG files containing HTML code to the /user/upload component of lenosp, which can lead to arbi...
Sep 14, 2023CVE-2023-41108 is an authenticated remote code execution vulnerability in TEF portal version 2023-07-17. Attackers with valid credentials can upload m...
Sep 5, 2023This vulnerability allows attackers to upload arbitrary files to the Gestione Documentale module in RealGimm 1.1.37p38, potentially leading to remote ...
Aug 31, 2023The FULL - Customer WordPress plugin up to version 2.2.3 contains an arbitrary file upload vulnerability via the /install-plugin REST route due to imp...
Aug 9, 2023CVE-2023-39346 is a remote code execution vulnerability in LinuxASMCallGraph software that allows attackers to execute arbitrary code on the server by...
Aug 4, 2023This vulnerability allows attackers to upload malicious files to Omeka-S web applications, potentially leading to remote code execution. It affects al...
Aug 4, 2023This vulnerability allows remote attackers to upload malicious files and execute arbitrary code on Typecho v1.2.1 installations. Attackers can exploit...
Aug 3, 2023CVE-2023-36212 is a file upload vulnerability in Total CMS v1.7.4 that allows remote attackers to upload crafted PHP files through the edit page funct...
Aug 3, 2023This vulnerability allows authenticated attackers to upload arbitrary files to EVERTZ devices, potentially enabling webshell deployment or critical sy...
Jul 18, 2023This vulnerability allows authenticated attackers to upload arbitrary files with root privileges on SonicWall GMS and Analytics systems. Attackers cou...
Jul 13, 2023This vulnerability allows authenticated privileged users in Zimbra Collaboration Suite to upload malicious files through the ClientUploader function, ...
Jul 6, 2023CMS Made Simple v2.2.17 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious files and execute arbitra...
Jul 6, 2023CVE-2020-21861 is an unrestricted file upload vulnerability in DuxCMS 2.1 that allows attackers to upload arbitrary PHP files through the admin upload...
Jul 6, 2023CVE-2023-36630 is an insecure file upload vulnerability in CloudPanel that allows attackers to upload malicious files without proper validation. This ...
Jun 25, 2023This vulnerability allows remote attackers to execute arbitrary code on WUZHI CMS systems via an unsafe file upload mechanism in the set_chache method...
Jun 20, 2023CVE-2020-20067 is a file upload vulnerability in ebCMS v1.1.0 that allows remote attackers to upload malicious files and execute arbitrary code on the...
Jun 20, 2023This vulnerability in the Unlimited Elements For Elementor WordPress plugin allows authenticated attackers with contributor-level permissions or highe...
Jun 17, 2023CVE-2023-33253 is a remote code execution vulnerability in LabCollector that allows authenticated low-privileged users to upload malicious PHP files a...
Jun 12, 2023CVE-2023-33498 is an access control vulnerability in Alist file listing software where low-privilege user accounts can upload any file type regardless...
Jun 7, 2023The AdSanity WordPress plugin up to version 1.8.1 contains a vulnerability that allows authenticated users with Contributor-level permissions or highe...
Jun 7, 2023This vulnerability allows attackers to upload arbitrary PHP files through the admin upload functionality in phpok v6.4.100, leading to remote code exe...
Jun 7, 2023This vulnerability in the PWA for WP & AMP WordPress plugin allows authenticated attackers to upload arbitrary files due to missing file type validati...
Jun 7, 2023This vulnerability allows remote attackers to execute arbitrary code on Genesys CIC Polycom phone provisioning TFTP servers by exploiting improper inp...
May 10, 2023MCMS 5.0 contains a file upload vulnerability that allows attackers to upload malicious files disguised as thumbnails, leading to arbitrary code execu...
May 8, 2023This vulnerability allows authenticated remote attackers to set the default storage path to the webroot directory in Jedox installations. Subsequent f...
May 2, 2023CLTPHP versions up to 6.0 contain an unrestricted file upload vulnerability that allows attackers to upload malicious files to the server. This affect...
Apr 26, 2023CVE-2023-27755 is an arbitrary file download vulnerability in go-bbs v1 that allows attackers to download any file from the server via the /api/v1/dow...
Apr 17, 2023Employee Performance Evaluation System v1.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the ser...
Apr 14, 2023Online Pizza Ordering v1.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the server. This can lea...
Apr 14, 2023This vulnerability in the JetEngine WordPress plugin allows attackers to upload files that can be executed as code, leading to remote code execution. ...
Apr 10, 2023CVE-2023-0265 is a remote code execution vulnerability in Uvdesk that allows authenticated attackers to execute arbitrary commands on the server by up...
Apr 4, 2023This vulnerability allows attackers to upload malicious PHP files through CSZ CMS's file upload functionality, leading to remote code execution. It af...
Mar 23, 2023This vulnerability allows attackers to upload malicious firmware to Netgear Nighthawk RAX30 routers by exploiting a hidden 'forceFWUpdate' parameter t...
Mar 15, 2023The Auto Featured Image WordPress plugin before version 3.9.16 contains an insecure AJAX endpoint that allows authenticated users with Author privileg...
Mar 13, 2023This vulnerability allows authenticated users to upload malicious PHP files to AvantFAX servers by bypassing file type validation. Attackers can execu...
Mar 10, 2023This vulnerability allows attackers to upload malicious files to the Cockpit CMS due to insufficient file type validation. It affects all users runnin...
Mar 10, 2023This CVE describes a remote code execution vulnerability in phpwcms where attackers can upload malicious files to execute arbitrary code on the server...
Feb 3, 2023CVE-2022-45968 allows authenticated users with file upload permission to upload arbitrary files to any folder in Alist v3.4.0, including password-prot...
Dec 12, 2022CVE-2022-34549 is an arbitrary file upload vulnerability in Sims v1.0 that allows attackers to upload malicious files via the /uploadServlet component...
Jul 27, 2022This vulnerability allows attackers to upload arbitrary PHP files through the Advertising Management module of Feehi CMS. Attackers can achieve remote...
Jul 27, 2022About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,476 CVEs classified as CWE-434, with 733 rated critical and 628 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free