CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,485
Total CVEs
741
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,485)

CVE-2026-2269
7.2

This vulnerability allows authenticated WordPress administrators to perform server-side request forgery (SSRF) attacks via the Uncanny Automator plugi...

Mar 3, 2026
CVE-2026-1065
7.2

The Form Maker by 10Web WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript code due to weak file ex...

Feb 3, 2026
CVE-2026-1400
7.2

This vulnerability in the AI Engine WordPress plugin allows authenticated attackers with Editor-level access or higher to upload arbitrary files, incl...

Jan 28, 2026
CVE-2022-50916
7.2

CVE-2022-50916 is a file upload vulnerability in e107 CMS version 3.2.1 that allows authenticated administrators to overwrite server files through Med...

Jan 13, 2026
CVE-2025-37175
7.2

This vulnerability allows authenticated attackers to upload arbitrary files to mobility conductors running AOS-10 or AOS-8 operating systems. Successf...

Jan 13, 2026
CVE-2026-22241
7.2

CVE-2026-22241 is an arbitrary file upload vulnerability in Open eClass (formerly GUnet eClass) that allows authenticated administrators to upload mal...

Jan 8, 2026
CVE-2023-53889
7.2

CVE-2023-53889 is a remote code execution vulnerability in Perch CMS 3.2 that allows authenticated administrators to upload malicious PHP files throug...

Dec 15, 2025
CVE-2023-53892
7.2

Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jqu...

Dec 15, 2025
CVE-2023-53885
7.2

Webutler v3.2 contains an arbitrary file upload vulnerability that allows authenticated administrators to upload PHP files containing system commands....

Dec 15, 2025
CVE-2024-58313
7.2

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated administrators to upload and execute arbitrary PHP code throug...

Dec 11, 2025
CVE-2024-58282
7.2

Serendipity 2.5.0 contains a remote code execution vulnerability where authenticated administrators can upload malicious PHP files through the media u...

Dec 10, 2025
CVE-2025-13376
7.2

The ProjectList WordPress plugin allows authenticated attackers with Editor-level access or higher to upload arbitrary files due to missing file type ...

Nov 25, 2025
CVE-2025-12973
7.2

This vulnerability allows authenticated attackers with Editor-level WordPress access to upload arbitrary files due to missing file type validation in ...

Nov 21, 2025
CVE-2025-0645
7.2

This vulnerability allows attackers to upload malicious files to Pyxis Signage systems, bypassing access controls. Attackers could execute arbitrary c...

Nov 20, 2025
CVE-2025-63227
7.2

This vulnerability allows authenticated attackers with administrative credentials to upload arbitrary files to the Mozart FM Transmitter web managemen...

Nov 18, 2025
CVE-2025-63678
7.2

This vulnerability allows authenticated administrators in CMS Made Simple Foundation File Manager v2.2.22 to upload arbitrary PHP files via the /uploa...

Nov 10, 2025
CVE-2025-12867
7.2

CVE-2025-12867 is an arbitrary file upload vulnerability in EIP Plus software developed by Hundred Plus. It allows authenticated remote attackers with...

Nov 10, 2025
CVE-2025-12399
7.2

The Alex Reservations WordPress plugin up to version 2.2.3 allows authenticated administrators to upload arbitrary files via a vulnerable REST API end...

Nov 8, 2025
CVE-2025-11967
7.2

The Mail Mint WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulnerability c...

Nov 8, 2025
CVE-2025-11889
7.2

The AIO Forms WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation in import functionali...

Oct 24, 2025
CVE-2025-60500
7.2

QDocs Smart School Management System 7.1 contains a logic flaw that allows authenticated users with roles like 'accountant' or 'admin' to bypass file ...

Oct 21, 2025
CVE-2025-10051
7.2

The Demo Import Kit WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to missing file type v...

Oct 15, 2025
CVE-2025-37132
7.2

An authenticated attacker can upload arbitrary files to the web management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor systems, pot...

Oct 14, 2025
CVE-2025-11675
7.2

CVE-2025-11675 is an arbitrary file upload vulnerability in Ragic's Enterprise Cloud Database that allows authenticated attackers with sufficient priv...

Oct 13, 2025
CVE-2025-10747
7.2

The WP-DownloadManager WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulner...

Sep 26, 2025
CVE-2025-57642
7.2

This vulnerability allows attackers to upload malicious PHP shell scripts to Tourism Management System 2.0 servers, enabling remote code execution and...

Sep 10, 2025
CVE-2025-10049
7.2

This vulnerability allows authenticated attackers with Administrator-level access or higher to upload arbitrary files to WordPress sites using the Res...

Sep 10, 2025
CVE-2025-10001
7.2

This vulnerability allows authenticated attackers with Administrator-level access to upload arbitrary files, including malicious .phar files, to WordP...

Sep 10, 2025
CVE-2025-9515
7.2

The Multi Step Form WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation in the import f...

Sep 6, 2025
CVE-2025-6085
7.2

The Make Connector WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to improper file type v...

Sep 4, 2025
CVE-2025-5322
7.2

The VikRentCar WordPress plugin up to version 1.4.3 allows authenticated administrators to upload arbitrary files due to missing file type validation....

Jul 3, 2025
CVE-2025-5961
7.2

The WPvivid Backup & Migration WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. Thi...

Jul 3, 2025
CVE-2025-4102
7.2

The Beaver Builder Plugin (Starter Version) for WordPress has a vulnerability allowing authenticated administrators to upload arbitrary files due to m...

Jun 20, 2025
CVE-2025-23171
7.2

This vulnerability in Versa Director SD-WAN orchestration platform allows authenticated attackers to upload malicious files despite UI restrictions, p...

Jun 19, 2025
CVE-2025-6220
7.2

The Ultra Addons for Contact Form 7 WordPress plugin has a vulnerability that allows authenticated administrators to upload arbitrary files due to mis...

Jun 18, 2025
CVE-2025-6086
7.2

The CSV Me WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to insufficient file type valid...

Jun 18, 2025
CVE-2025-3234
7.2

The File Manager Pro – Filester WordPress plugin allows authenticated attackers with Administrator-level access to upload arbitrary files due to mis...

Jun 14, 2025
CVE-2025-46612
7.2

This vulnerability allows remote attackers to execute arbitrary commands on Airleader Master and Easy systems by uploading malicious JSP files through...

Jun 10, 2025
CVE-2024-13723
7.2

CVE-2024-13723 is a remote code execution vulnerability in the NagVis component of Checkmk. Authenticated attackers with administrative privileges can...

Feb 4, 2025
CVE-2024-46210
7.2

An arbitrary file upload vulnerability in Redaxo CMS v5.17.1 allows attackers to upload malicious files through the MediaPool module. This can lead to...

Jan 10, 2025
CVE-2024-9698
7.2

The Crafthemes Demo Import WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to missing file...

Dec 14, 2024
CVE-2024-9504
7.2

This vulnerability allows unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when viewed. All WordPress sites...

Nov 26, 2024
CVE-2024-52769
7.2

This vulnerability allows attackers to upload malicious files to DedeBIZ CMS through the admin interface, potentially leading to remote code execution...

Nov 20, 2024
CVE-2024-51152
7.2

A file upload vulnerability in Laravel CMS v1.4.7 and earlier allows remote attackers to upload malicious PHP files (like shell.php) and execute arbit...

Nov 8, 2024
CVE-2024-48454
7.2

This vulnerability allows remote attackers to execute arbitrary code on SourceCodester Purchase Order Management System v1.0 via the /admin?page=user ...

Oct 24, 2024
CVE-2024-44871
7.2

This vulnerability allows attackers to upload arbitrary files to the moziloCMS admin interface, potentially leading to remote code execution. It affec...

Sep 10, 2024
CVE-2024-6311
7.2

The Funnelforms Free WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulnerab...

Aug 28, 2024
CVE-2024-42523
7.2

PublicCMS versions up to V4.0.202302.e contain an unrestricted file upload vulnerability in the template metadata management endpoint. This allows aut...

Aug 23, 2024
CVE-2024-39717
7.2

This vulnerability allows authenticated administrators in Versa Director to upload malicious files disguised as PNG images through the favicon customi...

Aug 22, 2024
CVE-2024-42767
7.2

Kashipara Hotel Management System v1.0 contains an unrestricted file upload vulnerability in the /admin/add_room_controller.php endpoint that allows r...

Aug 22, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free