CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,388
Total CVEs
693
Critical
580
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 18
2 Ivanti 12
3 Zohocorp 12
4 Phpgurukul 7
5 Oretnom23 7
6 Mingsoft 7
7 Dedecms 7
8 Netgear 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,388)

CVE-2024-49324
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to Sovratec Case Management web servers. Attackers can achieve re...

Oct 20, 2024
CVE-2024-49611
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress websites running the vulnerable Product Website Show...

Oct 20, 2024
CVE-2024-49314
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the JiangQie Free Mini Program plugi...

Oct 17, 2024
CVE-2024-49291
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the Cooked Pro plugin. Attackers can upload m...

Oct 17, 2024
CVE-2024-49242
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Digital Lottery plugin. Attacker...

Oct 16, 2024
CVE-2024-49257
10.0

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Azz Anonim Posting plugin. Attac...

Oct 16, 2024
CVE-2024-8940
10.0

CVE-2024-8940 is a critical unrestricted file upload vulnerability in Scriptcase version 9.4.019 that allows attackers to upload malicious files to th...

Sep 25, 2024
CVE-2024-43160
10.0

CVE-2024-43160 is an unauthenticated arbitrary file upload vulnerability in the BerqWP WordPress plugin that allows attackers to upload malicious file...

Aug 13, 2024
CVE-2024-35746
10.0

This vulnerability allows attackers to upload malicious files to WordPress sites using the BuddyPress Cover plugin, potentially leading to remote code...

Jun 10, 2024
CVE-2024-32809
10.0

This vulnerability allows attackers to upload malicious files to WordPress sites running the ActiveDEMAND plugin. Attackers can upload dangerous file ...

May 17, 2024
CVE-2024-31351
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the Copymatic plugin. Attackers can upload ma...

May 17, 2024
CVE-2024-32700
10.0

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the vulnerable Kognetiks Chatbot plugin. Attackers can upload...

May 14, 2024
CVE-2024-31377
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including malicious scripts, to WordPress sites running the vulnerable ...

May 14, 2024
CVE-2024-0916
10.0

This critical vulnerability in UvDesk Community allows unauthenticated attackers to upload malicious files and execute arbitrary code on affected syst...

Apr 25, 2024
CVE-2023-51409
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the vulnerable AI Engine plugin. Attackers ca...

Apr 12, 2024
CVE-2024-31115
10.0

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Chauffeur Taxi Booking System plugin. Attackers can uploa...

Mar 31, 2024
CVE-2023-49815
10.0

CVE-2023-49815 is an unauthenticated arbitrary file upload vulnerability in the WappPress WordPress plugin. Attackers can upload malicious files witho...

Mar 27, 2024
CVE-2023-23656
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the MainWP File Uploader Extension. This can le...

Mar 26, 2024
CVE-2024-25925
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the vulnerable WooCommerce Easy Checkout Fiel...

Feb 26, 2024
CVE-2023-52221
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the affected plugin, potentially leading to r...

Jan 24, 2024
CVE-2024-0643
10.0

CVE-2024-0643 is a critical unrestricted file upload vulnerability in C21 Live Encoder and Live Mosaic version 5.3 that allows remote attackers to upl...

Jan 17, 2024
CVE-2022-46839
10.0

This vulnerability allows attackers to upload arbitrary files to WordPress sites running the JS Help Desk plugin. Attackers can upload malicious files...

Jan 5, 2024
CVE-2023-51419
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files, including malicious scripts, to WordPress sites running the vulnerable ...

Dec 29, 2023
CVE-2023-51468
10.0

CVE-2023-51468 is an unauthenticated arbitrary file upload vulnerability in the Rencontre WordPress dating site plugin. Attackers can upload malicious...

Dec 29, 2023
CVE-2023-51475
10.0

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the WP MLM SOFTWARE PLUGIN. Attackers can upl...

Dec 29, 2023
CVE-2023-6723
10.0

CVE-2023-6723 is an unrestricted file upload vulnerability in Repbox that allows attackers to upload malicious files via the transforamationfileupload...

Dec 13, 2023
CVE-2022-47893
10.0

CVE-2022-47893 is a critical remote code execution vulnerability in NetMan 204 devices that allows attackers to upload malicious firmware containing a...

Oct 3, 2023
CVE-2023-35189
10.0

CVE-2023-35189 is a critical remote code execution vulnerability in Iagona ScrutisWeb versions 2.1.37 and earlier. Unauthenticated attackers can uploa...

Jul 18, 2023
CVE-2022-1519
10.0

This vulnerability allows unrestricted file uploads in LRM (Logistics Resource Management) systems, enabling attackers to upload malicious executable ...

Jun 24, 2022
CVE-2020-35489
10.0

This vulnerability in Contact Form 7 WordPress plugin allows unrestricted file upload due to improper filename validation. Attackers can upload malici...

Dec 17, 2020
CVE-2020-25213
10.0

This vulnerability allows remote attackers to upload and execute arbitrary PHP code on WordPress sites using the vulnerable wp-file-manager plugin. At...

Sep 9, 2020
CVE-2025-69403
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Bravis Addons plugin. It affects all WordPress installation...

Feb 20, 2026
CVE-2025-68549
9.9

This vulnerability allows attackers to upload malicious files, including web shells, to servers running the Wiguard WordPress theme. It affects all ve...

Feb 20, 2026
CVE-2025-57795
9.9

Explorance Blue versions before 8.14.13 contain an authenticated remote file download vulnerability that can be exploited to achieve remote code execu...

Jan 28, 2026
CVE-2025-68986
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running the Miion WordPress theme. Attackers can achie...

Jan 22, 2026
CVE-2025-68909
9.9

CVE-2025-68909 is an arbitrary file upload vulnerability in the Blogistic WordPress theme that allows attackers to upload malicious files without prop...

Jan 22, 2026
CVE-2025-68910
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Blogzee theme, potentially leading to complete system compr...

Jan 22, 2026
CVE-2025-67968
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Real Homes CRM plugin. Attackers can exploit this to execut...

Jan 22, 2026
CVE-2025-62050
9.9

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the Blogmatic theme, potentially leading to remote code executi...

Jan 22, 2026
CVE-2025-62056
9.9

The WordPress News Event theme (versions up to 1.0.1) contains an unrestricted file upload vulnerability that allows attackers to upload arbitrary fil...

Jan 22, 2026
CVE-2025-30996
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using affected Themify themes. It enables remo...

Jan 6, 2026
CVE-2025-68562
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to servers running vulnerable versions of the MapSVG WordPress pl...

Dec 29, 2025
CVE-2025-64374
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Motors theme. It affects all Motors theme installations fro...

Dec 18, 2025
CVE-2025-62047
9.9

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the Case Addons plugin, potentially leading to remote code exec...

Nov 6, 2025
CVE-2025-62016
9.9

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the Kallyas theme, potentially leading to remote code execution...

Nov 6, 2025
CVE-2025-63601
9.9

CVE-2025-63601 is a critical remote code execution vulnerability in Snipe-IT asset management software. Authenticated attackers can upload malicious b...

Nov 5, 2025
CVE-2025-58048
9.9

This vulnerability allows authenticated users in Paymenter webshop software to upload arbitrary files through ticket attachments. Attackers can exploi...

Aug 28, 2025
CVE-2025-53251
9.9

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Pin W...

Aug 21, 2025
CVE-2025-53213
9.9

This vulnerability allows attackers to upload malicious files to websites using the ReachShip WooCommerce Multi-Carrier & Conditional Shipping plugin....

Aug 20, 2025
CVE-2025-24775
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Made I.T. Forms plugin. Attacker...

Aug 14, 2025

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,388 CVEs classified as CWE-434, with 693 rated critical and 580 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free