CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,485
Total CVEs
741
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,485)

CVE-2024-40691
8.0

This vulnerability in IBM Cognos Controller allows attackers to upload malicious executable files through the web interface due to insufficient file v...

Dec 3, 2024
CVE-2024-47319
8.0

This vulnerability allows attackers to upload malicious files to WordPress sites using the Bit Form plugin, potentially leading to code execution. It ...

Oct 5, 2024
CVE-2024-33438
8.0

This CVE describes a file upload vulnerability in CubeCart e-commerce software that allows authenticated users to upload malicious .phar files, leadin...

Apr 29, 2024
CVE-2024-22135
8.0

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the WebToffee Order Export & Order Import for WooCommerce plugi...

Jan 24, 2024
CVE-2023-27881
8.0

This vulnerability allows authenticated users to upload files to arbitrary locations on the server filesystem through the 'Upload Resource' functional...

Jun 7, 2023
CVE-2022-2420
8.0

CVE-2022-2420 is a critical unrestricted file upload vulnerability in URVE Web Manager's uploader.php file. Attackers on the local network can upload ...

Jul 15, 2022
CVE-2022-2418
8.0

CVE-2022-2418 is a critical unrestricted file upload vulnerability in URVE Web Manager's img_upload.php component. Attackers with network access can u...

Jul 15, 2022
CVE-2022-1752
8.0

This vulnerability allows attackers to upload malicious files to the truDesk helpdesk software due to insufficient file type validation. Attackers cou...

May 21, 2022
CVE-2021-39040
8.0

CVE-2021-39040 is an unrestricted file upload vulnerability in IBM Planning Analytics Workspace 2.0 that allows attackers to upload malicious executab...

Apr 25, 2022
CVE-2021-23280
8.0

Eaton Intelligent Power Manager (IPM) versions before 1.69 allow authenticated attackers to upload arbitrary files, including malicious NodeJS code, v...

Apr 13, 2021
CVE-2020-4955
8.0

CVE-2020-4955 is a remote code execution vulnerability in IBM Spectrum Protect Operations Center that allows attackers to execute arbitrary code with ...

Feb 15, 2021
CVE-2020-4703
8.0

This vulnerability allows authenticated attackers to upload arbitrary files to IBM Spectrum Protect Plus Administrative Console, potentially leading t...

Sep 15, 2020
CVE-2024-13171
7.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager (EPM) systems by exploiting insufficie...

Jan 14, 2025
CVE-2024-47423
7.8

Adobe Framemaker versions 2020.6, 2022.4 and earlier contain an unrestricted file upload vulnerability (CWE-434) that could allow arbitrary code execu...

Oct 9, 2024
CVE-2024-45136
7.8

CVE-2024-45136 is an unrestricted file upload vulnerability in Adobe InCopy that allows attackers to upload malicious files which could lead to arbitr...

Oct 9, 2024
CVE-2023-25365
7.8

This vulnerability allows a local attacker to upload malicious .mp3 files containing XSS payloads to October CMS, which can then execute arbitrary Jav...

Feb 8, 2024
CVE-2023-44824
7.8

This vulnerability in Expense Management System v1.0 allows a local attacker to upload a malicious file to the sign-up.php component, leading to arbit...

Oct 17, 2023
CVE-2023-43838
7.8

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to upload malicious SVG files as user profile avatars, w...

Oct 4, 2023
CVE-2023-41902
7.8

This vulnerability allows attackers to escalate privileges on macOS systems by exploiting an XPC misconfiguration in CoreCode MacUpdater. Attackers ca...

Sep 20, 2023
CVE-2023-43619
7.8

CVE-2023-43619 is a vulnerability in Croc file transfer software that allows a malicious sender to transfer dangerous files to a receiver, potentially...

Sep 20, 2023
CVE-2023-39147
7.8

This vulnerability allows attackers to upload malicious image files to Uvdesk 1.1.3, which can lead to remote code execution on the server. Any organi...

Aug 1, 2023
CVE-2023-37208
7.8

Firefox and Thunderbird failed to warn users when opening Diagcab files, which could contain malicious code. This vulnerability allows attackers to ex...

Jul 5, 2023
CVE-2021-27280
7.8

CVE-2021-27280 is an OS command injection vulnerability in mblog 3.5.0 that allows attackers to execute arbitrary system commands by uploading a malic...

May 8, 2023
CVE-2022-29637
7.8

CVE-2022-29637 is an arbitrary file upload vulnerability in Mindoc documentation software that allows attackers to upload malicious Zip files containi...

May 26, 2022
CVE-2022-29623
7.8

CVE-2022-29623 is an arbitrary file upload vulnerability in Express Connect-Multiparty 2.2.0 that allows attackers to upload malicious PDF files, pote...

May 16, 2022
CVE-2022-22392
7.8

CVE-2022-22392 is an unrestricted file upload vulnerability in IBM Planning Analytics Local 2.0 that allows attackers to upload arbitrary executable f...

Apr 25, 2022
CVE-2020-26008
7.8

This vulnerability allows attackers to upload arbitrary PHP files to ShopXO v1.9.0 through the PluginsUpload function, leading to remote code executio...

Mar 20, 2022
CVE-2022-25581
7.8

Classcms v2.5 and below contains an arbitrary file upload vulnerability in the classupload component. Attackers can upload crafted .txt files to execu...

Mar 18, 2022
CVE-2022-25115
7.8

This vulnerability allows remote attackers to execute arbitrary code on Home Owners Collection Management System v1.0 by uploading a specially crafted...

Mar 2, 2022
CVE-2022-0409
7.8

CVE-2022-0409 is an unrestricted file upload vulnerability in showdoc documentation software that allows attackers to upload dangerous file types. Thi...

Feb 19, 2022
CVE-2022-0263
7.8

This vulnerability allows attackers to upload malicious files to Pimcore systems due to insufficient file type validation. It affects all Pimcore inst...

Jan 18, 2022
CVE-2020-20672
7.8

KiteCMS V1.1 contains an arbitrary file upload vulnerability in the /admin/upload/uploadfile endpoint that allows attackers to upload malicious PHP fi...

Sep 13, 2021
CVE-2020-19303
7.8

This vulnerability allows attackers to upload arbitrary files to hdcms 5.7 via the /fileupload.php endpoint, potentially leading to remote code execut...

Aug 3, 2021
CVE-2020-7864
7.8

CVE-2020-7864 is an authentication bypass vulnerability in Raonwiz DEXT5Editor that allows attackers to upload and execute arbitrary files through par...

Jun 15, 2021
CVE-2021-22698
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected systems by uploading a malicious SSD file. It affects EcoStruxure Pow...

Jan 26, 2021
CVE-2020-22721
7.8

This vulnerability in PNotes.NET allows a local attacker to upload malicious executable files through the 'External Programs' feature, leading to arbi...

Aug 14, 2020
CVE-2020-17462
7.8

CMS Made Simple 2.2.14 allows authenticated users to upload malicious .ptar files through the File Manager, potentially leading to arbitrary code exec...

Aug 14, 2020
CVE-2025-15067
7.7

This vulnerability allows attackers to upload malicious files to web servers running Innorix WP, potentially leading to remote code execution. All ver...

Dec 29, 2025
CVE-2024-37179
7.7

CVE-2024-37179 is an unrestricted file download vulnerability in SAP BusinessObjects Business Intelligence Platform. Authenticated attackers can explo...

Oct 8, 2024
CVE-2024-27733
7.7

A local file upload vulnerability in Byzro Network Smart s42 Management Platform allows attackers to upload malicious files and execute arbitrary code...

Mar 7, 2024
CVE-2025-60735
7.6

PerfreeBlog v4.0.11 contains an arbitrary file upload vulnerability in the installPlugin function that allows attackers to upload malicious files. Thi...

Oct 24, 2025
CVE-2024-56508
7.6

LinkAce versions before 1.15.6 contain a file upload vulnerability in the 'Import Bookmarks' feature that allows attackers to upload malicious HTML fi...

Dec 27, 2024
CVE-2023-41788
7.6

This vulnerability allows attackers to upload PHP files to Pandora FMS servers without proper restrictions, enabling remote code execution. It affects...

Nov 23, 2023
CVE-2025-13646
7.5

The Modula Image Gallery WordPress plugin versions 2.13.1 to 2.13.2 contain a vulnerability that allows authenticated attackers with Author-level perm...

Dec 3, 2025
CVE-2025-65844
7.5

CVE-2025-65844 is an unauthenticated arbitrary file upload vulnerability in EverShop 2.0.1 that allows attackers to upload any file type and create di...

Dec 2, 2025
CVE-2025-12048
7.5

An arbitrary file upload vulnerability in Lenovo Scanner Pro client allows attackers to upload malicious files that could lead to remote code executio...

Nov 12, 2025
CVE-2025-45586
7.5

This vulnerability in Audi UTR 2.0 Universal Traffic Recorder allows attackers to overwrite arbitrary files on the system by sending a specially craft...

Sep 12, 2025
CVE-2025-6207
7.5

The WP Import Export Lite WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing ...

Aug 5, 2025
CVE-2025-47187
7.5

This vulnerability allows unauthenticated attackers to upload arbitrary WAV files to affected Mitel SIP phones due to missing authentication mechanism...

Jul 23, 2025
CVE-2025-6206
7.5

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload arbitrary files to the server due to missing ...

Jun 24, 2025

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free