CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,485)
CVE-2023-50729 is an unrestricted file upload vulnerability in Traccar GPS tracking systems that allows attackers to upload malicious files to arbitra...
Jan 15, 2024This vulnerability allows attackers to upload arbitrary files to WordPress sites using vulnerable versions of the Slider Revolution plugin. Attackers ...
Dec 20, 2023This vulnerability allows authenticated admin users in SAP BusinessObjects Business Intelligence Platform (CMC) to upload malicious code that gets exe...
Feb 14, 2023FNT Command 13.4.0 contains a directory traversal vulnerability (CWE-434) that allows attackers to access files outside the intended directory. This a...
Dec 15, 2025This vulnerability allows attackers to execute arbitrary code on Eaton BLSS systems by exploiting improper file upload validation. It affects all Eato...
Nov 3, 2025FlowiseAI version 3.0.7 contains a file upload vulnerability that allows authenticated users to upload arbitrary files without validation. This enable...
Oct 6, 2025This vulnerability allows authenticated back-end users with file manager access in Contao CMS to upload malicious files and execute arbitrary code on ...
Sep 17, 2024This vulnerability allows attackers to upload malicious PHP files disguised as images through front-end forms in Statamic CMS. It affects websites usi...
Nov 10, 2023CVE-2018-25171 is an unauthenticated SQL injection vulnerability in EdTv 2 that allows attackers to execute arbitrary SQL queries through the 'id' par...
Mar 6, 2026A file upload vulnerability in Motivian Content Management System v41.0.0 allows remote attackers to upload arbitrary files, potentially leading to re...
Jun 4, 2025The Royal Elementor Addons and Templates WordPress plugin has a vulnerability that allows unauthenticated attackers to upload dangerous file types lik...
May 2, 2024HCL DRYiCE MyXalytics has an unauthenticated file upload vulnerability that allows attackers to upload malicious files without authentication. This af...
Jan 3, 2024This vulnerability allows remote attackers to execute arbitrary code on M-Files Web Companion servers by uploading specially crafted files. It affects...
Oct 20, 2023An authentication bypass vulnerability in PaperCut NG allows unauthenticated remote attackers to upload arbitrary files to the server's storage. This ...
Jul 25, 2023This vulnerability allows authenticated users to bypass file upload validation in Pimcore by adding a fake GIF signature to malicious files. Attackers...
Feb 3, 2023CVE-2020-25037 is a command injection vulnerability in UCOPIA Wi-Fi appliances that allows authenticated admin users to escape restricted commands and...
Feb 2, 2021This vulnerability allows attackers to upload malicious files to Teknoera software, potentially leading to file content injection attacks. It affects ...
Jan 22, 2026The Redirection for Contact Form 7 WordPress plugin allows unauthenticated attackers to upload arbitrary files to the server due to missing file type ...
Dec 21, 2025The SureMail WordPress plugin allows unauthenticated attackers to upload malicious PHP files through public forms that email attachments, leading to r...
Dec 2, 2025The Pie Forms for WP WordPress plugin has an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files like ...
Nov 18, 2025The Gravity Forms WordPress plugin allows unauthenticated attackers to upload .phar files through its legacy chunked upload mechanism, bypassing file ...
Nov 18, 2025The Booster for WooCommerce WordPress plugin allows unauthenticated attackers to upload arbitrary files with double extensions due to missing file typ...
Aug 29, 2025This vulnerability allows authenticated admin users in Grav CMS to upload malicious plugins through the direct-install interface, leading to arbitrary...
Aug 6, 2025The BerqWP WordPress plugin has an unauthenticated arbitrary file upload vulnerability that allows attackers to upload malicious files to the server. ...
Aug 1, 2025This vulnerability in Firefox and Thunderbird allows saved files from the Network tab in Devtools to lack the .download extension, potentially causing...
Jun 24, 2025This vulnerability allows unauthenticated attackers to upload malicious files like .phar extensions to WordPress sites using the Drag and Drop Multipl...
Jun 17, 2025The eMagicOne Store Manager for WooCommerce WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type valid...
May 24, 2025An insecure file upload vulnerability in Verydows v2.0 allows remote attackers to upload malicious files and execute arbitrary code on the server. Thi...
Apr 9, 2025The Booster for WooCommerce WordPress plugin versions 4.0.1 through 7.2.4 contain an arbitrary file upload vulnerability due to missing file type vali...
Apr 4, 2025The Product Input Fields for WooCommerce WordPress plugin has an arbitrary file upload vulnerability due to insufficient file type validation. Unauthe...
Mar 8, 2025This vulnerability allows attackers to upload malicious files to affected Schneider Electric devices, potentially rendering them inoperable. The issue...
Feb 13, 2025An arbitrary file upload vulnerability in JeeWMS allows attackers to upload malicious files that can lead to remote code execution. This affects all J...
Jan 15, 2025Sage 1000 v7.0.0 contains an unrestricted file upload vulnerability that allows authorized users to upload malicious files without proper validation. ...
Oct 30, 2024MCMS v5.4.1 has an unauthenticated front-end file upload vulnerability that allows attackers to upload malicious files and execute arbitrary commands ...
Sep 3, 2024This vulnerability allows unauthenticated attackers to upload malicious files to WordPress sites using the Metform Elementor Contact Form Builder plug...
Aug 17, 2024CVE-2023-46694 is an arbitrary file upload vulnerability in Vtenext 21.02 that allows authenticated attackers to upload malicious files through the Ck...
May 28, 2024Phpgurukul Tourism Management System v2.0 contains an unrestricted file upload vulnerability in the admin panel's change-image.php endpoint. Attackers...
Apr 16, 2024The Piotnet Forms WordPress plugin up to version 1.0.26 allows unauthenticated attackers to upload arbitrary files due to insufficient file type valid...
Jan 11, 2024This vulnerability allows attackers to upload malicious files to Mobatime web servers through documentary proof upload modules. Attackers can upload w...
Jun 2, 2023Kiwi TCMS versions before 12.2 allow unrestricted file uploads, enabling attackers to upload malicious files like executables or JavaScript-containing...
Apr 24, 2023Judging Management System 1.0 contains an arbitrary file upload vulnerability in edit_organizer.php that allows attackers to upload malicious files, p...
Feb 23, 2023This vulnerability in Ivanti Avalanche allows attackers with access to the Inforail Service to write arbitrary files to the system. This could lead to...
Dec 7, 2021Machform versions before 16 allow unauthenticated attackers to execute arbitrary code on the server by uploading malicious file attachments through fo...
Jun 29, 2021This vulnerability allows remote attackers to execute arbitrary PHP code on servers running vulnerable versions of elFinder file manager. Attackers ca...
Jun 13, 2021This vulnerability in E-POINT CMS allows attackers to upload nested ZIP archives containing executable files like webshells. When extracted, these fil...
Dec 4, 2025IBM Planning Analytics 2.0 and 2.1 have a file upload vulnerability that allows attackers to upload malicious executable files through the web interfa...
Jan 24, 2025IBM Planning Analytics 2.0 and 2.1 have a file upload vulnerability in the File Manager T1 process that allows attackers to upload malicious executabl...
Jan 24, 2025This vulnerability in Optimizely EPiServer CMS Core allows attackers to upload malicious files like .docm and .html due to improper file validation. W...
Jan 4, 2025IBM Cognos Analytics has a file upload vulnerability that allows attackers to upload malicious executable files through the web interface without prop...
Dec 20, 2024A vulnerability in Digi ConnectPort LTS devices allows attackers to manipulate file paths during uploads via POST requests, enabling arbitrary file up...
Dec 9, 2024About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free