CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,482
Total CVEs
738
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,482)

CVE-2021-36121
8.8

CVE-2021-36121 is an unrestricted file upload vulnerability in Echo ShareCare 8.15.5 that allows authenticated users to upload arbitrary files to arbi...

Jul 13, 2021
CVE-2021-28931
8.8

CVE-2021-28931 is an arbitrary file upload vulnerability in Fork CMS that allows attackers to upload malicious zip files to the Themes panel, enabling...

Jul 7, 2021
CVE-2020-36388
8.8

This vulnerability allows authenticated users to upload and execute malicious PHAR archives in CiviCRM, potentially leading to remote code execution. ...

Jun 17, 2021
CVE-2021-32243
8.8

CVE-2021-32243 is an authenticated file upload vulnerability in FOGProject that allows remote code execution. Attackers with valid credentials can upl...

Jun 16, 2021
CVE-2021-27489
8.8

This vulnerability allows non-administrative users to upload malicious files to the ZOLL Defibrillator Dashboard web application, potentially enabling...

Jun 16, 2021
CVE-2021-34128
8.8

CVE-2021-34128 is an arbitrary file upload vulnerability in LaikeTui e-commerce software that allows authenticated attackers to upload ZIP archives co...

Jun 15, 2021
CVE-2021-26828
8.8

This vulnerability allows remote authenticated users to upload and execute arbitrary JSP files via the view_edit.shtm endpoint in ScadaBR. This leads ...

Jun 11, 2021
CVE-2020-36141
8.8

CVE-2020-36141 is an unrestricted file upload vulnerability in BloofoxCMS that allows attackers to bypass MIME type validation by inserting 'image/jpe...

Jun 4, 2021
CVE-2021-29092
8.8

This vulnerability allows remote authenticated users to upload malicious files to Synology Photo Station, which can lead to arbitrary code execution. ...

Jun 1, 2021
CVE-2021-24311
8.8

This vulnerability allows any authenticated WordPress user to upload arbitrary files via the wp_ajax_upload-remote-file AJAX action in the External Me...

Jun 1, 2021
CVE-2020-26678
8.8

CVE-2020-26678 is a remote code execution vulnerability in vFairs 3.3 that allows authenticated users to upload malicious PHP files via profile pictur...

May 26, 2021
CVE-2021-32094
8.8

CVE-2021-32094 allows authenticated users to upload arbitrary files to NSA Emissary workflow application. This could lead to remote code execution or ...

May 7, 2021
CVE-2021-24224
8.8

This vulnerability in the Easy Form Builder WordPress plugin allows authenticated users with low privileges to upload arbitrary files without security...

Apr 12, 2021
CVE-2021-28379
8.8

This vulnerability in Vesta Control Panel allows attackers to upload files from different origins due to improper access controls in the upload handle...

Mar 15, 2021
CVE-2021-27513
8.8

CVE-2021-27513 is an arbitrary file upload vulnerability in the admin_ITSM module of EyesOfNetwork 5.3-10 that allows authenticated attackers to uploa...

Feb 22, 2021
CVE-2021-3164
8.8

CVE-2021-3164 allows authenticated users in ChurchRota to upload and execute arbitrary files via a POST request to resources.php, even without file up...

Jan 26, 2021
CVE-2020-24549
8.8

CVE-2020-24549 is an unrestricted file upload vulnerability in openMAINT that allows authenticated users to upload arbitrary JSP files to the web serv...

Jan 26, 2021
CVE-2020-19364
8.8

CVE-2020-19364 is an unrestricted file upload vulnerability in OpenEMR that allows authenticated attackers to upload and execute malicious PHP scripts...

Jan 20, 2021
CVE-2020-35627
8.8

This vulnerability in Ultimate WooCommerce Gift Cards allows attackers to upload malicious PHP files disguised as images, leading to remote code execu...

Dec 28, 2020
CVE-2020-27397
8.8

CVE-2020-27397 is an authenticated file upload vulnerability in Marital - Online Matrimonial Project in PHP version 1.0 that allows attackers to uploa...

Dec 23, 2020
CVE-2020-26174
8.8

This vulnerability allows attackers to bypass client-side file upload restrictions in tangro Business Workflow, enabling them to upload any file type ...

Dec 18, 2020
CVE-2020-7569
8.8

This vulnerability allows authenticated remote attackers to upload arbitrary files to EcoStruxure Building Operation WebReports servers, potentially l...

Nov 19, 2020
CVE-2020-28687
8.8

This vulnerability allows remote attackers to upload arbitrary files through the edit profile functionality in ARTWORKS GALLERY software. Attackers ca...

Nov 17, 2020
CVE-2020-28693
8.8

This vulnerability allows authenticated attackers to upload malicious PHP files disguised as themes via zip archives in HorizontCMS. Once uploaded, th...

Nov 16, 2020
CVE-2020-26804
8.8

This vulnerability allows authenticated attackers to upload malicious files through Sentrifugo's announcement attachment feature, potentially leading ...

Nov 12, 2020
CVE-2020-28328
8.8

This vulnerability in SuiteCRM allows remote code execution by manipulating the Log File Name setting to point to an attacker-controlled PHP file. It ...

Nov 6, 2020
CVE-2020-12715
8.8

CVE-2020-12715 is an incorrect access control vulnerability in RainbowFish PacsOne Server 6.8.4 that allows unauthenticated attackers to bypass authen...

Sep 30, 2020
CVE-2020-21564
8.8

Pluck CMS 4.7.10-dev2 and 4.7.11 contain a file upload vulnerability in the admin.php?action=files endpoint that allows authenticated attackers to upl...

Sep 30, 2020
CVE-2020-4620
8.8

This vulnerability allows authenticated remote attackers to upload malicious files to IBM Data Risk Manager (iDNA) due to improper file extension vali...

Sep 22, 2020
CVE-2020-10228
8.8

This vulnerability allows authenticated users in vtecrm vtenext 19 CE to upload malicious .pht files, which can lead to remote code execution on the s...

Sep 14, 2020
CVE-2020-15645
8.8

This vulnerability in Marvell QConvergeConsole allows authenticated remote attackers to bypass authentication and execute arbitrary code with SYSTEM p...

Aug 25, 2020
CVE-2025-23213
8.7

Tandoor Recipes versions before 1.5.28 contain an unrestricted file upload vulnerability that allows attackers to upload malicious HTML and SVG files ...

Jan 28, 2025
CVE-2023-42472
8.7

This vulnerability allows authenticated attackers to bypass file type validation in SAP BusinessObjects Business Intelligence Platform's Web Intellige...

Sep 12, 2023
CVE-2025-55383
8.6

Moss versions before 0.15 have an unrestricted file upload vulnerability that allows attackers to upload arbitrary files to any location on the server...

Aug 21, 2025
CVE-2025-45997
8.6

This vulnerability allows attackers to upload malicious PHP files disguised as images to the Web-based Pharmacy Product Management System v1.0. By mod...

May 28, 2025
CVE-2021-21355
8.6

This vulnerability allows unauthenticated attackers to upload arbitrary files with any extension to TYPO3 CMS servers. It affects TYPO3 installations ...

Mar 23, 2021
CVE-2020-3436
8.6

This vulnerability allows unauthenticated remote attackers to upload arbitrarily large files to specific folders on Cisco ASA and Firepower Threat Def...

Oct 21, 2020
CVE-2025-24801
8.5

This vulnerability allows authenticated GLPI users to upload and execute arbitrary PHP files on the server, leading to remote code execution. It affec...

Mar 18, 2025
CVE-2023-25921
8.5

This vulnerability in IBM Security Guardium Key Lifecycle Manager allows attackers to upload dangerous file types that can be automatically processed ...

Feb 29, 2024
CVE-2021-39154
8.5

CVE-2021-39154 is a remote code execution vulnerability in XStream library that allows attackers to execute arbitrary code by manipulating XML input s...

Aug 23, 2021
CVE-2021-39146
8.5

CVE-2021-39146 is a remote code execution vulnerability in XStream library that allows attackers to execute arbitrary code by manipulating XML input s...

Aug 23, 2021
CVE-2021-39148
8.5

CVE-2021-39148 is a remote code execution vulnerability in XStream library that allows attackers to execute arbitrary code by manipulating XML input s...

Aug 23, 2021
CVE-2021-39151
8.5

CVE-2021-39151 is a remote code execution vulnerability in XStream library versions before 1.4.18. Attackers can manipulate XML input to execute arbit...

Aug 23, 2021
CVE-2021-39139
8.5

CVE-2021-39139 is a remote code execution vulnerability in XStream library that allows attackers to execute arbitrary code by manipulating XML input s...

Aug 23, 2021
CVE-2025-10907
8.4

An arbitrary file upload vulnerability in WSO2 products allows authenticated administrators to upload malicious files to user-controlled locations via...

Nov 5, 2025
CVE-2025-4648
8.4

This vulnerability allows reflected cross-site scripting (XSS) in Centreon web interface via malicious SVG file uploads. An authenticated user with el...

May 13, 2025
CVE-2024-41340
8.4

This vulnerability in Draytek routers allows attackers to upload malicious APP Enforcement modules, leading to arbitrary code execution with root priv...

Feb 27, 2025
CVE-2023-50729
8.4

CVE-2023-50729 is an unrestricted file upload vulnerability in Traccar GPS tracking systems that allows attackers to upload malicious files to arbitra...

Jan 15, 2024
CVE-2023-47784
8.4

This vulnerability allows attackers to upload arbitrary files to WordPress sites using vulnerable versions of the Slider Revolution plugin. Attackers ...

Dec 20, 2023
CVE-2023-24530
8.4

This vulnerability allows authenticated admin users in SAP BusinessObjects Business Intelligence Platform (CMC) to upload malicious code that gets exe...

Feb 14, 2023

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,482 CVEs classified as CWE-434, with 738 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free