CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,485
Total CVEs
741
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,485)

CVE-2025-1025
7.5

CVE-2025-1025 is an arbitrary file upload vulnerability in Cockpit CMS where attackers can bypass upload filters using different file extensions. This...

Feb 5, 2025
CVE-2024-13333
7.5

The Advanced File Manager WordPress plugin versions 5.2.12 to 5.2.13 allow authenticated attackers with Subscriber-level access and upload permissions...

Jan 17, 2025
CVE-2024-11391
7.5

The Advanced File Manager WordPress plugin allows authenticated attackers with Subscriber-level access to upload arbitrary files due to missing file t...

Dec 3, 2024
CVE-2024-8066
7.5

The File Manager Pro – Filester WordPress plugin up to version 1.8.6 allows authenticated attackers with Subscriber-level access (and administrator-...

Nov 28, 2024
CVE-2024-10668
7.5

This vulnerability allows attackers to bypass Google Quick Share's file validation by sending duplicate file transfer frames, enabling them to upload ...

Nov 7, 2024
CVE-2024-7985
7.5

The FileOrganizer WordPress plugin allows authenticated users with Subscriber-level access or higher to upload arbitrary files due to missing file typ...

Oct 29, 2024
CVE-2024-8746
7.5

The File Manager Pro WordPress plugin allows unauthenticated attackers to download and upload arbitrary backup files through an AJAX endpoint without ...

Oct 16, 2024
CVE-2024-8126
7.5

The Advanced File Manager WordPress plugin allows authenticated attackers with Subscriber-level access to upload arbitrary files, including .htaccess ...

Sep 26, 2024
CVE-2024-7384
7.5

The AcyMailing WordPress plugin has a vulnerability that allows authenticated users with Subscriber-level access or higher to upload arbitrary files d...

Aug 22, 2024
CVE-2024-22641
7.5

TCPDF versions 6.6.5 and earlier contain a Regular Expression Denial of Service (ReDoS) vulnerability when processing untrusted SVG files. Attackers c...

May 28, 2024
CVE-2024-30533
7.5

This vulnerability allows attackers to upload arbitrary files, including malicious scripts, to WordPress sites using the vulnerable Layouts for Elemen...

Mar 31, 2024
CVE-2024-28425
7.5

Greykite v1.0.0 contains an arbitrary file upload vulnerability in the load_obj function that allows attackers to upload malicious pickle files. When ...

Mar 14, 2024
CVE-2023-40183
7.5

This vulnerability in DataEase allows attackers to upload malicious files disguised as images that can steal user cookies when accessed. It affects al...

Sep 21, 2023
CVE-2020-19028
7.5

This vulnerability allows remote attackers to upload arbitrary files via the /admin/plugin.php endpoint in EmlogCMS v6.0.0. Attackers can gain unautho...

Jun 5, 2023
CVE-2023-22890
7.5

SmartBear Zephyr Enterprise versions through 7.15.0 allow unauthenticated users to upload large files without authentication, which can fill up local ...

Mar 8, 2023
CVE-2023-25402
7.5

CVE-2023-25402 is an unrestricted file upload vulnerability in CleverStupidDog yf-exam 1.8.0 that allows attackers to upload arbitrary files without s...

Mar 3, 2023
CVE-2021-33615
7.5

CVE-2021-33615 is an unrestricted file upload vulnerability in RSA Archer 6.8 that allows attackers to upload malicious files to the server. This affe...

Jun 2, 2022
CVE-2021-33009
7.5

CVE-2021-33009 allows unauthenticated remote attackers to upload arbitrary files to the mySCADA myPRO system file system. This affects mySCADA myPRO v...

May 13, 2022
CVE-2021-37105
7.5

CVE-2021-37105 is an improper file upload vulnerability in Huawei FusionCompute virtualization software. Attackers can upload malicious files without ...

Sep 28, 2021
CVE-2021-40524
7.5

This vulnerability in Pure-FTPd allows attackers to bypass file size quotas and upload files of unlimited size, potentially causing denial of service ...

Sep 5, 2021
CVE-2021-3166
7.5

This vulnerability allows attackers to upload arbitrary files disguised as firmware updates to ASUS DSL-N14U-B1 routers. When the malicious file uses ...

Jan 18, 2021
CVE-2020-26286
7.5

CVE-2020-26286 is an unrestricted file upload vulnerability in HedgeDoc that allows unauthenticated attackers to upload arbitrary files including HTML...

Dec 29, 2020
CVE-2020-15488
7.5

CVE-2020-15488 is an insecure file upload vulnerability in Re:Desk 2.3 help desk software that allows attackers to upload malicious files without prop...

Sep 30, 2020
CVE-2020-25733
7.5

CVE-2020-25733 is an unrestricted file upload vulnerability in webTareas that allows attackers to upload dangerous .exe and .shtml files. This can lea...

Sep 18, 2020
CVE-2020-1469
7.5

This vulnerability allows attackers to cause a denial of service (DoS) by sending specially crafted input to applications using the .NET implementatio...

Jul 14, 2020
CVE-2024-28147
7.4

This vulnerability allows authenticated users to upload malicious files in edu-sharing's collection preview image upload function. Attackers can uploa...

Jun 20, 2024
CVE-2021-43829
7.4

CVE-2021-43829 is an unrestricted file upload vulnerability in PatrOwl Manager's findings import feature. Attackers can upload malicious files leading...

Dec 14, 2021
CVE-2020-7847
7.4

CVE-2020-7847 is an arbitrary file upload vulnerability in ipTIME NAS devices that allows attackers to upload malicious files through the Manage Bulle...

Feb 23, 2021
CVE-2025-59118
7.3

This vulnerability allows attackers to upload malicious files to Apache OFBiz servers, potentially leading to remote code execution or server compromi...

Nov 12, 2025
CVE-2025-56295
7.3

Computer Laboratory System 1.0 has an unrestricted file upload vulnerability that allows authenticated staff users to upload PHP backdoor files throug...

Sep 16, 2025
CVE-2025-26498
7.3

This vulnerability allows attackers to upload malicious files to Salesforce Tableau Server and traverse directory paths to write files to arbitrary lo...

Aug 22, 2025
CVE-2024-6373
7.3

This critical vulnerability allows remote attackers to upload arbitrary files to the Online Food Ordering System via the /addproduct.php endpoint. Att...

Jun 27, 2024
CVE-2024-6115
7.3

This critical vulnerability in Simple Online Hotel Reservation System 1.0 allows remote attackers to upload arbitrary files via the photo parameter in...

Jun 18, 2024
CVE-2024-6110
7.3

This critical vulnerability in the Magbanua Beach Resort Online Reservation System allows remote attackers to upload arbitrary files via the 'image' p...

Jun 18, 2024
CVE-2024-6084
7.3

This critical vulnerability allows remote attackers to upload arbitrary files to the Pool of Bethesda Online Reservation System via the uploadImage fu...

Jun 18, 2024
CVE-2024-5745
7.3

CVE-2024-5745 is a critical unrestricted file upload vulnerability in itsourcecode Bakery Online Ordering System 1.0. Attackers can remotely upload ma...

Jun 7, 2024
CVE-2024-5377
7.3

This vulnerability allows remote attackers to upload arbitrary files to the Vehicle Management System 1.0 via the /newvehicle.php endpoint. Attackers ...

May 26, 2024
CVE-2024-5047
7.3

This critical vulnerability in SourceCodester Student Management System 1.0 allows attackers to upload arbitrary files via the photo parameter in /stu...

May 17, 2024
CVE-2024-4966
7.3

This critical vulnerability in SourceCodester SchoolWebTech 1.0 allows attackers to upload arbitrary files via the /improve/home.php endpoint. Attacke...

May 16, 2024
CVE-2024-4920
7.3

This critical vulnerability in SourceCodester Online Discussion Forum Site 1.0 allows attackers to upload arbitrary files without restrictions via the...

May 16, 2024
CVE-2024-3437
7.3

This critical vulnerability in SourceCodester Prison Management System 1.0 allows remote attackers to upload arbitrary files via the avatar handler in...

Apr 8, 2024
CVE-2024-1036
7.3

This vulnerability allows remote attackers to upload arbitrary files to openBI systems due to insufficient validation in the Icon Handler component. A...

Jan 30, 2024
CVE-2024-1034
7.3

This critical vulnerability in openBI allows attackers to upload arbitrary files without restrictions via the uploadFile function. This affects all op...

Jan 30, 2024
CVE-2024-0648
7.3

This critical vulnerability in Yunyou CMS allows remote attackers to upload arbitrary files without restrictions by manipulating the templateFile para...

Jan 17, 2024
CVE-2024-20272
7.3

An unauthenticated remote attacker can upload arbitrary files and execute commands on Cisco Unity Connection systems via a vulnerable API in the web m...

Jan 17, 2024
CVE-2024-0352
7.3

This critical vulnerability in Likeshop allows attackers to upload arbitrary files without restrictions via the FileServer::userFormImage function. Re...

Jan 9, 2024
CVE-2023-2523
7.3

This critical vulnerability in Weaver E-Office 9.5 allows remote attackers to upload arbitrary files without restrictions via the mobile_upload_save f...

May 4, 2023
CVE-2023-1734
7.3

This critical vulnerability in SourceCodester Young Entrepreneur E-Negosyo System 1.0 allows remote attackers to upload arbitrary files via the image ...

Mar 30, 2023
CVE-2021-42123
7.3

This vulnerability allows authenticated users with upload privileges to upload files of any type to the TopEase platform. Attackers can upload malicio...

Nov 30, 2021
CVE-2020-25406
7.3

This vulnerability in LemoCMS 1.8.x allows authenticated users to upload executable files through the upload functionality, bypassing intended file ty...

Nov 18, 2020

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free