CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,478)
This vulnerability allows attackers to upload arbitrary PHP files through the Advertising Management module of Feehi CMS. Attackers can achieve remote...
Jul 27, 2022Arox School ERP Pro v1.0 contains multiple arbitrary file upload vulnerabilities that allow attackers to upload malicious files to the server. This af...
Jul 15, 2022Microweber 1.1.3 has an arbitrary file upload vulnerability that allows attackers to upload malicious files disguised as pictures, potentially leading...
Jul 15, 2022An unrestricted file upload vulnerability in Strapi 4.1.12 allows authenticated users with upload permissions to upload PDF files containing JavaScrip...
Jul 13, 2022CVE-2015-1784 is an arbitrary file upload vulnerability in the NextGEN Gallery WordPress plugin that allows attackers to upload malicious files and ex...
Jul 7, 2022The User Photo WordPress plugin version 0.9.4 has insufficient file upload validation, allowing attackers to upload malicious PHP files disguised as i...
Jun 24, 2022CVE-2022-2111 is an unrestricted file upload vulnerability in InvenTree inventory management software that allows attackers to upload malicious files ...
Jun 17, 2022CVE-2022-30820 is an arbitrary file upload vulnerability in Wedding Management v1.0 that allows attackers to upload malicious files through the pictur...
Jun 2, 2022Wedding Management System v1.0 contains an arbitrary file upload vulnerability in the users_profile.php picture upload function. This allows attackers...
Jun 2, 2022CVE-2022-29624 is an arbitrary file upload vulnerability in TPCMS v3.2 that allows attackers to upload malicious PHP files through the Add File functi...
Jun 2, 2022The Advanced Uploader WordPress plugin through version 4.2 contains an unrestricted file upload vulnerability that allows any authenticated user (incl...
May 16, 2022The SP Project & Document Manager WordPress plugin before version 4.24 contains an insufficient file extension validation vulnerability on Windows ser...
Apr 25, 2022This vulnerability in the Elementor Website Builder plugin for WordPress allows authenticated attackers to execute unauthorized AJAX actions due to mi...
Apr 19, 2022This vulnerability allows unauthenticated attackers to upload malicious PHP files to BigAnt Office Messenger servers via the im_webserver component. A...
Apr 7, 2022Online Project Time Management System v1.0 contains an arbitrary file write vulnerability that allows attackers to upload crafted HTML files and achie...
Apr 7, 2022This vulnerability allows attackers to upload arbitrary files including webshells via the product image upload feature in Ecommerce-Website v1.1.0. At...
Apr 4, 2022Car Rental System v1.0 contains an arbitrary file upload vulnerability in the Add Car component that allows attackers to upload malicious files like w...
Apr 4, 2022This vulnerability allows authenticated remote attackers to upload malicious ASPX files to IdeaRE RefTree web servers, leading to remote code executio...
Apr 3, 2022The Amelia WordPress plugin before version 1.0.47 allows authenticated users with the 'Amelia Manager' role to upload files with arbitrary extensions,...
Mar 21, 2022This vulnerability allows remote attackers to upload malicious web shell scripts through the file manager in Croogo CMS, leading to remote code execut...
Mar 10, 2022An authenticated attacker with low privileges can upload malicious files disguised as MP3s to execute arbitrary code on Quicklert for Digium servers. ...
Mar 10, 2022Extensis Portfolio v4.0 contains an authenticated unrestricted file upload vulnerability in the Catalog Asset Upload function. This allows authenticat...
Mar 1, 2022Extensis Portfolio v4.0 contains an authenticated unrestricted file upload vulnerability in the AdminFileTransferServlet component. This allows authen...
Mar 1, 2022CVE-2022-25360 allows authenticated remote attackers with unprivileged credentials to upload files to arbitrary locations on WatchGuard Firebox and XT...
Feb 24, 2022WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability where attackers can upload malicious files through the image upload f...
Feb 19, 2022This vulnerability allows remote attackers to execute arbitrary commands on Voipmonitor GUI systems by uploading a malicious file to the web root. Att...
Feb 4, 2022CVE-2021-46113 is a remote code execution vulnerability in KEA-Hotel-ERP open source software that allows attackers to upload malicious PHP files thro...
Jan 25, 2022This vulnerability in ownCloud's files_antivirus component allows malicious files uploaded to public shares to persist even after antivirus detection....
Jan 15, 2022CVE-2021-34995 is an authentication bypass vulnerability in Commvault CommCell that allows authenticated attackers to upload arbitrary files and execu...
Jan 13, 2022This vulnerability allows authenticated remote attackers to bypass authentication mechanisms and upload arbitrary files to Commvault CommCell installa...
Jan 13, 2022This vulnerability allows authenticated remote attackers to upload arbitrary files to SysAid ITIL servers via the /UploadPsIcon.jsp endpoint. Successf...
Jan 11, 2022This vulnerability allows unauthenticated attackers to upload malicious PHP files to the Vehicle Service Management System 1.0, leading to remote code...
Jan 6, 2022CVE-2021-36719 is an unrestricted file upload vulnerability in PineApp Mail Secure's nicUpload.php file that allows authenticated attackers to upload ...
Dec 8, 2021This vulnerability allows remote attackers to upload malicious scripts and execute arbitrary code on Grand Vice info Co. webopac7 systems. Attackers w...
Nov 15, 2021This vulnerability allows authenticated users to execute arbitrary code on Pentaho servers by exploiting BeanShell script inclusion in report (.prpt) ...
Nov 8, 2021This vulnerability allows remote attackers to upload arbitrary PHP files through the account update and customer creation features in Sourcecodester C...
Oct 27, 2021Tran Tu Air Sender v1.0.2 contains an arbitrary file upload vulnerability in its upload module that allows attackers to upload malicious files and exe...
Oct 22, 2021SuiteCRM versions before 7.11.19 allow remote code execution via the Log File Name setting in system settings. Attackers who compromise admin accounts...
Oct 22, 2021CVE-2021-3846 is an unrestricted file upload vulnerability in Firefly III personal finance software that allows attackers to upload dangerous file typ...
Oct 19, 2021CVE-2021-41919 is an unrestricted file upload vulnerability in webTareas that allows authenticated users to upload dangerous files via the profile pic...
Oct 8, 2021This vulnerability allows authenticated users with business authorization in SAP Business One to upload arbitrary files, including malicious scripts, ...
Sep 15, 2021This vulnerability allows attackers to upload arbitrary HTML files to the ZKEACMS admin media upload endpoint, which can lead to remote code execution...
Sep 13, 2021This vulnerability in the WordPress Simple Ecommerce Shopping Cart Plugin allows administrators to upload arbitrary files, including PHP files, withou...
Sep 13, 2021This vulnerability allows authenticated users in IBM OpenPages with Watson to upload malicious files that can execute arbitrary code on the server. It...
Aug 31, 2021This vulnerability allows authenticated users in Sitecore to upload arbitrary files, including malicious .aspx files, leading to remote code execution...
Aug 12, 2021This vulnerability allows authenticated attackers to upload arbitrary files to Trend Micro security products due to improper input validation. Attacke...
Jul 29, 2021CVE-2021-36121 is an unrestricted file upload vulnerability in Echo ShareCare 8.15.5 that allows authenticated users to upload arbitrary files to arbi...
Jul 13, 2021CVE-2021-28931 is an arbitrary file upload vulnerability in Fork CMS that allows attackers to upload malicious zip files to the Themes panel, enabling...
Jul 7, 2021This vulnerability allows authenticated users to upload and execute malicious PHAR archives in CiviCRM, potentially leading to remote code execution. ...
Jun 17, 2021CVE-2021-32243 is an authenticated file upload vulnerability in FOGProject that allows remote code execution. Attackers with valid credentials can upl...
Jun 16, 2021About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,478 CVEs classified as CWE-434, with 734 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free