CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,485
Total CVEs
741
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,485)

CVE-2023-50729
8.4

CVE-2023-50729 is an unrestricted file upload vulnerability in Traccar GPS tracking systems that allows attackers to upload malicious files to arbitra...

Jan 15, 2024
CVE-2023-47784
8.4

This vulnerability allows attackers to upload arbitrary files to WordPress sites using vulnerable versions of the Slider Revolution plugin. Attackers ...

Dec 20, 2023
CVE-2023-24530
8.4

This vulnerability allows authenticated admin users in SAP BusinessObjects Business Intelligence Platform (CMC) to upload malicious code that gets exe...

Feb 14, 2023
CVE-2024-44599
8.3

FNT Command 13.4.0 contains a directory traversal vulnerability (CWE-434) that allows attackers to access files outside the intended directory. This a...

Dec 15, 2025
CVE-2025-48396
8.3

This vulnerability allows attackers to execute arbitrary code on Eaton BLSS systems by exploiting improper file upload validation. It affects all Eato...

Nov 3, 2025
CVE-2025-61687
8.3

FlowiseAI version 3.0.7 contains a file upload vulnerability that allows authenticated users to upload arbitrary files without validation. This enable...

Oct 6, 2025
CVE-2024-45398
8.3

This vulnerability allows authenticated back-end users with file manager access in Contao CMS to upload malicious files and execute arbitrary code on ...

Sep 17, 2024
CVE-2023-47129
8.3

This vulnerability allows attackers to upload malicious PHP files disguised as images through front-end forms in Statamic CMS. It affects websites usi...

Nov 10, 2023
CVE-2018-25171
8.2

CVE-2018-25171 is an unauthenticated SQL injection vulnerability in EdTv 2 that allows attackers to execute arbitrary SQL queries through the 'id' par...

Mar 6, 2026
CVE-2025-29093
8.2

A file upload vulnerability in Motivian Content Management System v41.0.0 allows remote attackers to upload arbitrary files, potentially leading to re...

Jun 4, 2025
CVE-2024-1567
8.2

The Royal Elementor Addons and Templates WordPress plugin has a vulnerability that allows unauthenticated attackers to upload dangerous file types lik...

May 2, 2024
CVE-2023-45724
8.2

HCL DRYiCE MyXalytics has an unauthenticated file upload vulnerability that allows attackers to upload malicious files without authentication. This af...

Jan 3, 2024
CVE-2023-5524
8.2

This vulnerability allows remote attackers to execute arbitrary code on M-Files Web Companion servers by uploading specially crafted files. It affects...

Oct 20, 2023
CVE-2023-3486
8.2

An authentication bypass vulnerability in PaperCut NG allows unauthenticated remote attackers to upload arbitrary files to the server's storage. This ...

Jul 25, 2023
CVE-2023-23937
8.2

This vulnerability allows authenticated users to bypass file upload validation in Pimcore by adding a fake GIF signature to malicious files. Attackers...

Feb 3, 2023
CVE-2020-25037
8.2

CVE-2020-25037 is a command injection vulnerability in UCOPIA Wi-Fi appliances that allows authenticated admin users to escape restricted commands and...

Feb 2, 2021
CVE-2025-10856
8.1

This vulnerability allows attackers to upload malicious files to Teknoera software, potentially leading to file content injection attacks. It affects ...

Jan 22, 2026
CVE-2025-14800
8.1

The Redirection for Contact Form 7 WordPress plugin allows unauthenticated attackers to upload arbitrary files to the server due to missing file type ...

Dec 21, 2025
CVE-2025-13516
8.1

The SureMail WordPress plugin allows unauthenticated attackers to upload malicious PHP files through public forms that email attachments, leading to r...

Dec 2, 2025
CVE-2025-12528
8.1

The Pie Forms for WP WordPress plugin has an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files like ...

Nov 18, 2025
CVE-2025-12974
8.1

The Gravity Forms WordPress plugin allows unauthenticated attackers to upload .phar files through its legacy chunked upload mechanism, bypassing file ...

Nov 18, 2025
CVE-2024-13342
8.1

The Booster for WooCommerce WordPress plugin allows unauthenticated attackers to upload arbitrary files with double extensions due to missing file typ...

Aug 29, 2025
CVE-2025-50286
8.1

This vulnerability allows authenticated admin users in Grav CMS to upload malicious plugins through the direct-install interface, leading to arbitrary...

Aug 6, 2025
CVE-2025-7443
8.1

The BerqWP WordPress plugin has an unauthenticated arbitrary file upload vulnerability that allows attackers to upload malicious files to the server. ...

Aug 1, 2025
CVE-2025-6435
8.1

This vulnerability in Firefox and Thunderbird allows saved files from the Network tab in Devtools to lack the .download extension, potentially causing...

Jun 24, 2025
CVE-2025-3515
8.1

This vulnerability allows unauthenticated attackers to upload malicious files like .phar extensions to WordPress sites using the Drag and Drop Multipl...

Jun 17, 2025
CVE-2025-4336
8.1

The eMagicOne Store Manager for WooCommerce WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type valid...

May 24, 2025
CVE-2025-29394
8.1

An insecure file upload vulnerability in Verydows v2.0 allows remote attackers to upload malicious files and execute arbitrary code on the server. Thi...

Apr 9, 2025
CVE-2024-13744
8.1

The Booster for WooCommerce WordPress plugin versions 4.0.1 through 7.2.4 contain an arbitrary file upload vulnerability due to missing file type vali...

Apr 4, 2025
CVE-2024-13359
8.1

The Product Input Fields for WooCommerce WordPress plugin has an arbitrary file upload vulnerability due to insufficient file type validation. Unauthe...

Mar 8, 2025
CVE-2025-1070
8.1

This vulnerability allows attackers to upload malicious files to affected Schneider Electric devices, potentially rendering them inoperable. The issue...

Feb 13, 2025
CVE-2024-57761
8.1

An arbitrary file upload vulnerability in JeeWMS allows attackers to upload malicious files that can lead to remote code execution. This affects all J...

Jan 15, 2025
CVE-2024-48646
8.1

Sage 1000 v7.0.0 contains an unrestricted file upload vulnerability that allows authorized users to upload malicious files without proper validation. ...

Oct 30, 2024
CVE-2024-42991
8.1

MCMS v5.4.1 has an unauthenticated front-end file upload vulnerability that allows attackers to upload malicious files and execute arbitrary commands ...

Sep 3, 2024
CVE-2023-0714
8.1

This vulnerability allows unauthenticated attackers to upload malicious files to WordPress sites using the Metform Elementor Contact Form Builder plug...

Aug 17, 2024
CVE-2023-46694
8.1

CVE-2023-46694 is an arbitrary file upload vulnerability in Vtenext 21.02 that allows authenticated attackers to upload malicious files through the Ck...

May 28, 2024
CVE-2024-32256
8.1

Phpgurukul Tourism Management System v2.0 contains an unrestricted file upload vulnerability in the admin panel's change-image.php endpoint. Attackers...

Apr 16, 2024
CVE-2023-6220
8.1

The Piotnet Forms WordPress plugin up to version 1.0.26 allows unauthenticated attackers to upload arbitrary files due to insufficient file type valid...

Jan 11, 2024
CVE-2023-3032
8.1

This vulnerability allows attackers to upload malicious files to Mobatime web servers through documentary proof upload modules. Attackers can upload w...

Jun 2, 2023
CVE-2023-30613
8.1

Kiwi TCMS versions before 12.2 allow unrestricted file uploads, enabling attackers to upload malicious files like executables or JavaScript-containing...

Apr 24, 2023
CVE-2023-24317
8.1

Judging Management System 1.0 contains an arbitrary file upload vulnerability in edit_organizer.php that allows attackers to upload malicious files, p...

Feb 23, 2023
CVE-2021-42133
8.1

This vulnerability in Ivanti Avalanche allows attackers with access to the Inforail Service to write arbitrary files to the system. This could lead to...

Dec 7, 2021
CVE-2021-20104
8.1

Machform versions before 16 allow unauthenticated attackers to execute arbitrary code on the server by uploading malicious file attachments through fo...

Jun 29, 2021
CVE-2021-23394
8.1

This vulnerability allows remote attackers to execute arbitrary PHP code on servers running vulnerable versions of elFinder file manager. Attackers ca...

Jun 13, 2021
CVE-2025-65806
8.0

This vulnerability in E-POINT CMS allows attackers to upload nested ZIP archives containing executable files like webshells. When extracted, these fil...

Dec 4, 2025
CVE-2024-40693
8.0

IBM Planning Analytics 2.0 and 2.1 have a file upload vulnerability that allows attackers to upload malicious executable files through the web interfa...

Jan 24, 2025
CVE-2024-25034
8.0

IBM Planning Analytics 2.0 and 2.1 have a file upload vulnerability in the File Manager T1 process that allows attackers to upload malicious executabl...

Jan 24, 2025
CVE-2025-22389
8.0

This vulnerability in Optimizely EPiServer CMS Core allows attackers to upload malicious files like .docm and .html due to improper file validation. W...

Jan 4, 2025
CVE-2024-40695
8.0

IBM Cognos Analytics has a file upload vulnerability that allows attackers to upload malicious executable files through the web interface without prop...

Dec 20, 2024
CVE-2024-50625
8.0

A vulnerability in Digi ConnectPort LTS devices allows attackers to manipulate file paths during uploads via POST requests, enabling arbitrary file up...

Dec 9, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free