CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,485)
CVE-2025-1025 is an arbitrary file upload vulnerability in Cockpit CMS where attackers can bypass upload filters using different file extensions. This...
Feb 5, 2025The Advanced File Manager WordPress plugin versions 5.2.12 to 5.2.13 allow authenticated attackers with Subscriber-level access and upload permissions...
Jan 17, 2025The Advanced File Manager WordPress plugin allows authenticated attackers with Subscriber-level access to upload arbitrary files due to missing file t...
Dec 3, 2024The File Manager Pro – Filester WordPress plugin up to version 1.8.6 allows authenticated attackers with Subscriber-level access (and administrator-...
Nov 28, 2024This vulnerability allows attackers to bypass Google Quick Share's file validation by sending duplicate file transfer frames, enabling them to upload ...
Nov 7, 2024The FileOrganizer WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing file typ...
Oct 29, 2024The File Manager Pro WordPress plugin allows unauthenticated attackers to download and upload arbitrary backup files through an AJAX endpoint without ...
Oct 16, 2024The Advanced File Manager WordPress plugin allows authenticated attackers with Subscriber-level access to upload arbitrary files, including .htaccess ...
Sep 26, 2024The AcyMailing WordPress plugin has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload arbitrary files d...
Aug 22, 2024TCPDF versions 6.6.5 and earlier contain a Regular Expression Denial of Service (ReDoS) vulnerability when processing untrusted SVG files. Attackers c...
May 28, 2024This vulnerability allows attackers to upload arbitrary files, including malicious scripts, to WordPress sites using the vulnerable Layouts for Elemen...
Mar 31, 2024Greykite v1.0.0 contains an arbitrary file upload vulnerability in the load_obj function that allows attackers to upload malicious pickle files. When ...
Mar 14, 2024This vulnerability in DataEase allows attackers to upload malicious files disguised as images that can steal user cookies when accessed. It affects al...
Sep 21, 2023This vulnerability allows remote attackers to upload arbitrary files via the /admin/plugin.php endpoint in EmlogCMS v6.0.0. Attackers can gain unautho...
Jun 5, 2023SmartBear Zephyr Enterprise versions through 7.15.0 allow unauthenticated users to upload large files without authentication, which can fill up local ...
Mar 8, 2023CVE-2023-25402 is an unrestricted file upload vulnerability in CleverStupidDog yf-exam 1.8.0 that allows attackers to upload arbitrary files without s...
Mar 3, 2023CVE-2021-33615 is an unrestricted file upload vulnerability in RSA Archer 6.8 that allows attackers to upload malicious files to the server. This affe...
Jun 2, 2022CVE-2021-33009 allows unauthenticated remote attackers to upload arbitrary files to the mySCADA myPRO system file system. This affects mySCADA myPRO v...
May 13, 2022CVE-2021-37105 is an improper file upload vulnerability in Huawei FusionCompute virtualization software. Attackers can upload malicious files without ...
Sep 28, 2021This vulnerability in Pure-FTPd allows attackers to bypass file size quotas and upload files of unlimited size, potentially causing denial of service ...
Sep 5, 2021This vulnerability allows attackers to upload arbitrary files disguised as firmware updates to ASUS DSL-N14U-B1 routers. When the malicious file uses ...
Jan 18, 2021CVE-2020-26286 is an unrestricted file upload vulnerability in HedgeDoc that allows unauthenticated attackers to upload arbitrary files including HTML...
Dec 29, 2020CVE-2020-15488 is an insecure file upload vulnerability in Re:Desk 2.3 help desk software that allows attackers to upload malicious files without prop...
Sep 30, 2020CVE-2020-25733 is an unrestricted file upload vulnerability in webTareas that allows attackers to upload dangerous .exe and .shtml files. This can lea...
Sep 18, 2020This vulnerability allows attackers to cause a denial of service (DoS) by sending specially crafted input to applications using the .NET implementatio...
Jul 14, 2020This vulnerability allows authenticated users to upload malicious files in edu-sharing's collection preview image upload function. Attackers can uploa...
Jun 20, 2024CVE-2021-43829 is an unrestricted file upload vulnerability in PatrOwl Manager's findings import feature. Attackers can upload malicious files leading...
Dec 14, 2021CVE-2020-7847 is an arbitrary file upload vulnerability in ipTIME NAS devices that allows attackers to upload malicious files through the Manage Bulle...
Feb 23, 2021This vulnerability allows attackers to upload malicious files to Apache OFBiz servers, potentially leading to remote code execution or server compromi...
Nov 12, 2025Computer Laboratory System 1.0 has an unrestricted file upload vulnerability that allows authenticated staff users to upload PHP backdoor files throug...
Sep 16, 2025This vulnerability allows attackers to upload malicious files to Salesforce Tableau Server and traverse directory paths to write files to arbitrary lo...
Aug 22, 2025This critical vulnerability allows remote attackers to upload arbitrary files to the Online Food Ordering System via the /addproduct.php endpoint. Att...
Jun 27, 2024This critical vulnerability in Simple Online Hotel Reservation System 1.0 allows remote attackers to upload arbitrary files via the photo parameter in...
Jun 18, 2024This critical vulnerability in the Magbanua Beach Resort Online Reservation System allows remote attackers to upload arbitrary files via the 'image' p...
Jun 18, 2024This critical vulnerability allows remote attackers to upload arbitrary files to the Pool of Bethesda Online Reservation System via the uploadImage fu...
Jun 18, 2024CVE-2024-5745 is a critical unrestricted file upload vulnerability in itsourcecode Bakery Online Ordering System 1.0. Attackers can remotely upload ma...
Jun 7, 2024This vulnerability allows remote attackers to upload arbitrary files to the Vehicle Management System 1.0 via the /newvehicle.php endpoint. Attackers ...
May 26, 2024This critical vulnerability in SourceCodester Student Management System 1.0 allows attackers to upload arbitrary files via the photo parameter in /stu...
May 17, 2024This critical vulnerability in SourceCodester SchoolWebTech 1.0 allows attackers to upload arbitrary files via the /improve/home.php endpoint. Attacke...
May 16, 2024This critical vulnerability in SourceCodester Online Discussion Forum Site 1.0 allows attackers to upload arbitrary files without restrictions via the...
May 16, 2024This critical vulnerability in SourceCodester Prison Management System 1.0 allows remote attackers to upload arbitrary files via the avatar handler in...
Apr 8, 2024This vulnerability allows remote attackers to upload arbitrary files to openBI systems due to insufficient validation in the Icon Handler component. A...
Jan 30, 2024This critical vulnerability in openBI allows attackers to upload arbitrary files without restrictions via the uploadFile function. This affects all op...
Jan 30, 2024This critical vulnerability in Yunyou CMS allows remote attackers to upload arbitrary files without restrictions by manipulating the templateFile para...
Jan 17, 2024An unauthenticated remote attacker can upload arbitrary files and execute commands on Cisco Unity Connection systems via a vulnerable API in the web m...
Jan 17, 2024This critical vulnerability in Likeshop allows attackers to upload arbitrary files without restrictions via the FileServer::userFormImage function. Re...
Jan 9, 2024This critical vulnerability in Weaver E-Office 9.5 allows remote attackers to upload arbitrary files without restrictions via the mobile_upload_save f...
May 4, 2023This critical vulnerability in SourceCodester Young Entrepreneur E-Negosyo System 1.0 allows remote attackers to upload arbitrary files via the image ...
Mar 30, 2023This vulnerability allows authenticated users with upload privileges to upload files of any type to the TopEase platform. Attackers can upload malicio...
Nov 30, 2021This vulnerability in LemoCMS 1.8.x allows authenticated users to upload executable files through the upload functionality, bypassing intended file ty...
Nov 18, 2020About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free