CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,476
Total CVEs
733
Critical
628
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Mingsoft 7

All Unrestricted File Upload CVEs (1,476)

CVE-2023-46428
8.8

An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to upload malicious files that can lead to remote code execution. This affe...

Nov 1, 2023
CVE-2023-46815
8.8

SugarCRM has an unrestricted file upload vulnerability in the Notes module that allows authenticated users to upload malicious PHP files. This affects...

Oct 27, 2023
CVE-2023-45353
8.8

This vulnerability allows authenticated attackers to upload arbitrary files and execute code on the underlying operating system through the Unify Open...

Oct 9, 2023
CVE-2023-44061
8.8

This vulnerability allows remote attackers to upload malicious files through the edit profile component in Simple and Nice Shopping Cart Script v1.0, ...

Oct 6, 2023
CVE-2023-43321
8.8

This CVE describes an authenticated command injection vulnerability in Digital China Networks DCFW-1800-SDC firewall devices. An attacker with valid c...

Oct 4, 2023
CVE-2023-4097
8.8

This vulnerability allows authenticated attackers to upload arbitrary files to the affected application, potentially leading to remote code execution ...

Oct 3, 2023
CVE-2023-38874
8.8

This vulnerability allows remote attackers to execute arbitrary code on Economizzer servers by uploading malicious PHP files as attachments. Attackers...

Sep 28, 2023
CVE-2023-42331
8.8

This vulnerability in EliteCMS v1.01 allows remote attackers to upload arbitrary files through the manage_uploads.php component, potentially leading t...

Sep 20, 2023
CVE-2023-42335
8.8

An unrestricted file upload vulnerability in Fl3xx Dispatch and Crew versions 2.10.37 allows remote attackers to upload malicious files via the add at...

Sep 20, 2023
CVE-2023-36319
8.8

CVE-2023-36319 is a file upload vulnerability in Openupload Stable v0.4.3 that allows remote attackers to execute arbitrary code via the compress-inc....

Sep 20, 2023
CVE-2023-42180
8.8

This vulnerability allows attackers to upload malicious JPG files containing HTML code to the /user/upload component of lenosp, which can lead to arbi...

Sep 14, 2023
CVE-2023-41108
8.8

CVE-2023-41108 is an authenticated remote code execution vulnerability in TEF portal version 2023-07-17. Attackers with valid credentials can upload m...

Sep 5, 2023
CVE-2023-41638
8.8

This vulnerability allows attackers to upload arbitrary files to the Gestione Documentale module in RealGimm 1.1.37p38, potentially leading to remote ...

Aug 31, 2023
CVE-2023-4243
8.8

The FULL - Customer WordPress plugin up to version 2.2.3 contains an arbitrary file upload vulnerability via the /install-plugin REST route due to imp...

Aug 9, 2023
CVE-2023-39346
8.8

CVE-2023-39346 is a remote code execution vulnerability in LinuxASMCallGraph software that allows attackers to execute arbitrary code on the server by...

Aug 4, 2023
CVE-2023-4159
8.8

This vulnerability allows attackers to upload malicious files to Omeka-S web applications, potentially leading to remote code execution. It affects al...

Aug 4, 2023
CVE-2023-36299
8.8

This vulnerability allows remote attackers to upload malicious files and execute arbitrary code on Typecho v1.2.1 installations. Attackers can exploit...

Aug 3, 2023
CVE-2023-36212
8.8

CVE-2023-36212 is a file upload vulnerability in Total CMS v1.7.4 that allows remote attackers to upload crafted PHP files through the edit page funct...

Aug 3, 2023
CVE-2020-22159
8.8

This vulnerability allows authenticated attackers to upload arbitrary files to EVERTZ devices, potentially enabling webshell deployment or critical sy...

Jul 18, 2023
CVE-2023-34126
8.8

This vulnerability allows authenticated attackers to upload arbitrary files with root privileges on SonicWall GMS and Analytics systems. Attackers cou...

Jul 13, 2023
CVE-2023-34193
8.8

This vulnerability allows authenticated privileged users in Zimbra Collaboration Suite to upload malicious files through the ClientUploader function, ...

Jul 6, 2023
CVE-2023-36969
8.8

CMS Made Simple v2.2.17 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious files and execute arbitra...

Jul 6, 2023
CVE-2020-21861
8.8

CVE-2020-21861 is an unrestricted file upload vulnerability in DuxCMS 2.1 that allows attackers to upload arbitrary PHP files through the admin upload...

Jul 6, 2023
CVE-2023-36630
8.8

CVE-2023-36630 is an insecure file upload vulnerability in CloudPanel that allows attackers to upload malicious files without proper validation. This ...

Jun 25, 2023
CVE-2020-21325
8.8

This vulnerability allows remote attackers to execute arbitrary code on WUZHI CMS systems via an unsafe file upload mechanism in the set_chache method...

Jun 20, 2023
CVE-2020-20067
8.8

CVE-2020-20067 is a file upload vulnerability in ebCMS v1.1.0 that allows remote attackers to upload malicious files and execute arbitrary code on the...

Jun 20, 2023
CVE-2023-3295
8.8

This vulnerability in the Unlimited Elements For Elementor WordPress plugin allows authenticated attackers with contributor-level permissions or highe...

Jun 17, 2023
CVE-2023-33253
8.8

CVE-2023-33253 is a remote code execution vulnerability in LabCollector that allows authenticated low-privileged users to upload malicious PHP files a...

Jun 12, 2023
CVE-2023-33498
8.8

CVE-2023-33498 is an access control vulnerability in Alist file listing software where low-privilege user accounts can upload any file type regardless...

Jun 7, 2023
CVE-2022-4949
8.8

The AdSanity WordPress plugin up to version 1.8.1 contains a vulnerability that allows authenticated users with Contributor-level permissions or highe...

Jun 7, 2023
CVE-2023-33601
8.8

This vulnerability allows attackers to upload arbitrary PHP files through the admin upload functionality in phpok v6.4.100, leading to remote code exe...

Jun 7, 2023
CVE-2021-4354
8.8

This vulnerability in the PWA for WP & AMP WordPress plugin allows authenticated attackers to upload arbitrary files due to missing file type validati...

Jun 7, 2023
CVE-2023-29930
8.8

This vulnerability allows remote attackers to execute arbitrary code on Genesys CIC Polycom phone provisioning TFTP servers by exploiting improper inp...

May 10, 2023
CVE-2020-22755
8.8

MCMS 5.0 contains a file upload vulnerability that allows attackers to upload malicious files disguised as thumbnails, leading to arbitrary code execu...

May 8, 2023
CVE-2022-47878
8.8

This vulnerability allows authenticated remote attackers to set the default storage path to the webroot directory in Jedox installations. Subsequent f...

May 2, 2023
CVE-2023-30266
8.8

CLTPHP versions up to 6.0 contain an unrestricted file upload vulnerability that allows attackers to upload malicious files to the server. This affect...

Apr 26, 2023
CVE-2023-27755
8.8

CVE-2023-27755 is an arbitrary file download vulnerability in go-bbs v1 that allows attackers to download any file from the server via the /api/v1/dow...

Apr 17, 2023
CVE-2023-29625
8.8

Employee Performance Evaluation System v1.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the ser...

Apr 14, 2023
CVE-2023-29627
8.8

Online Pizza Ordering v1.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files to the server. This can lea...

Apr 14, 2023
CVE-2023-1406
8.8

This vulnerability in the JetEngine WordPress plugin allows attackers to upload files that can be executed as code, leading to remote code execution. ...

Apr 10, 2023
CVE-2023-0265
8.8

CVE-2023-0265 is a remote code execution vulnerability in Uvdesk that allows authenticated attackers to execute arbitrary commands on the server by up...

Apr 4, 2023
CVE-2020-19786
8.8

This vulnerability allows attackers to upload malicious PHP files through CSZ CMS's file upload functionality, leading to remote code execution. It af...

Mar 23, 2023
CVE-2023-28337
8.8

This vulnerability allows attackers to upload malicious firmware to Netgear Nighthawk RAX30 routers by exploiting a hidden 'forceFWUpdate' parameter t...

Mar 15, 2023
CVE-2023-0477
8.8

The Auto Featured Image WordPress plugin before version 3.9.16 contains an insecure AJAX endpoint that allows authenticated users with Author privileg...

Mar 13, 2023
CVE-2023-23328
8.8

This vulnerability allows authenticated users to upload malicious PHP files to AvantFAX servers by bypassing file type validation. Attackers can execu...

Mar 10, 2023
CVE-2023-1313
8.8

This vulnerability allows attackers to upload malicious files to the Cockpit CMS due to insufficient file type validation. It affects all users runnin...

Mar 10, 2023
CVE-2021-36426
8.8

This CVE describes a remote code execution vulnerability in phpwcms where attackers can upload malicious files to execute arbitrary code on the server...

Feb 3, 2023
CVE-2022-45968
8.8

CVE-2022-45968 allows authenticated users with file upload permission to upload arbitrary files to any folder in Alist v3.4.0, including password-prot...

Dec 12, 2022
CVE-2022-34549
8.8

CVE-2022-34549 is an arbitrary file upload vulnerability in Sims v1.0 that allows attackers to upload malicious files via the /uploadServlet component...

Jul 27, 2022
CVE-2022-34971
8.8

This vulnerability allows attackers to upload arbitrary PHP files through the Advertising Management module of Feehi CMS. Attackers can achieve remote...

Jul 27, 2022

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,476 CVEs classified as CWE-434, with 733 rated critical and 628 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free