CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,485)
This vulnerability allows authenticated WordPress administrators to perform server-side request forgery (SSRF) attacks via the Uncanny Automator plugi...
Mar 3, 2026The Form Maker by 10Web WordPress plugin allows unauthenticated attackers to upload malicious SVG files containing JavaScript code due to weak file ex...
Feb 3, 2026This vulnerability in the AI Engine WordPress plugin allows authenticated attackers with Editor-level access or higher to upload arbitrary files, incl...
Jan 28, 2026CVE-2022-50916 is a file upload vulnerability in e107 CMS version 3.2.1 that allows authenticated administrators to overwrite server files through Med...
Jan 13, 2026This vulnerability allows authenticated attackers to upload arbitrary files to mobility conductors running AOS-10 or AOS-8 operating systems. Successf...
Jan 13, 2026CVE-2026-22241 is an arbitrary file upload vulnerability in Open eClass (formerly GUnet eClass) that allows authenticated administrators to upload mal...
Jan 8, 2026CVE-2023-53889 is a remote code execution vulnerability in Perch CMS 3.2 that allows authenticated administrators to upload malicious PHP files throug...
Dec 15, 2025Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jqu...
Dec 15, 2025Webutler v3.2 contains an arbitrary file upload vulnerability that allows authenticated administrators to upload PHP files containing system commands....
Dec 15, 2025xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated administrators to upload and execute arbitrary PHP code throug...
Dec 11, 2025Serendipity 2.5.0 contains a remote code execution vulnerability where authenticated administrators can upload malicious PHP files through the media u...
Dec 10, 2025The ProjectList WordPress plugin allows authenticated attackers with Editor-level access or higher to upload arbitrary files due to missing file type ...
Nov 25, 2025This vulnerability allows authenticated attackers with Editor-level WordPress access to upload arbitrary files due to missing file type validation in ...
Nov 21, 2025This vulnerability allows attackers to upload malicious files to Pyxis Signage systems, bypassing access controls. Attackers could execute arbitrary c...
Nov 20, 2025This vulnerability allows authenticated attackers with administrative credentials to upload arbitrary files to the Mozart FM Transmitter web managemen...
Nov 18, 2025This vulnerability allows authenticated administrators in CMS Made Simple Foundation File Manager v2.2.22 to upload arbitrary PHP files via the /uploa...
Nov 10, 2025CVE-2025-12867 is an arbitrary file upload vulnerability in EIP Plus software developed by Hundred Plus. It allows authenticated remote attackers with...
Nov 10, 2025The Alex Reservations WordPress plugin up to version 2.2.3 allows authenticated administrators to upload arbitrary files via a vulnerable REST API end...
Nov 8, 2025The Mail Mint WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulnerability c...
Nov 8, 2025The AIO Forms WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation in import functionali...
Oct 24, 2025QDocs Smart School Management System 7.1 contains a logic flaw that allows authenticated users with roles like 'accountant' or 'admin' to bypass file ...
Oct 21, 2025The Demo Import Kit WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to missing file type v...
Oct 15, 2025An authenticated attacker can upload arbitrary files to the web management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor systems, pot...
Oct 14, 2025CVE-2025-11675 is an arbitrary file upload vulnerability in Ragic's Enterprise Cloud Database that allows authenticated attackers with sufficient priv...
Oct 13, 2025The WP-DownloadManager WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulner...
Sep 26, 2025This vulnerability allows attackers to upload malicious PHP shell scripts to Tourism Management System 2.0 servers, enabling remote code execution and...
Sep 10, 2025This vulnerability allows authenticated attackers with Administrator-level access or higher to upload arbitrary files to WordPress sites using the Res...
Sep 10, 2025This vulnerability allows authenticated attackers with Administrator-level access to upload arbitrary files, including malicious .phar files, to WordP...
Sep 10, 2025The Multi Step Form WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation in the import f...
Sep 6, 2025The Make Connector WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to improper file type v...
Sep 4, 2025The VikRentCar WordPress plugin up to version 1.4.3 allows authenticated administrators to upload arbitrary files due to missing file type validation....
Jul 3, 2025The WPvivid Backup & Migration WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. Thi...
Jul 3, 2025The Beaver Builder Plugin (Starter Version) for WordPress has a vulnerability allowing authenticated administrators to upload arbitrary files due to m...
Jun 20, 2025This vulnerability in Versa Director SD-WAN orchestration platform allows authenticated attackers to upload malicious files despite UI restrictions, p...
Jun 19, 2025The Ultra Addons for Contact Form 7 WordPress plugin has a vulnerability that allows authenticated administrators to upload arbitrary files due to mis...
Jun 18, 2025The CSV Me WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to insufficient file type valid...
Jun 18, 2025The File Manager Pro – Filester WordPress plugin allows authenticated attackers with Administrator-level access to upload arbitrary files due to mis...
Jun 14, 2025This vulnerability allows remote attackers to execute arbitrary commands on Airleader Master and Easy systems by uploading malicious JSP files through...
Jun 10, 2025CVE-2024-13723 is a remote code execution vulnerability in the NagVis component of Checkmk. Authenticated attackers with administrative privileges can...
Feb 4, 2025An arbitrary file upload vulnerability in Redaxo CMS v5.17.1 allows attackers to upload malicious files through the MediaPool module. This can lead to...
Jan 10, 2025The Crafthemes Demo Import WordPress plugin allows authenticated attackers with Administrator privileges to upload arbitrary files due to missing file...
Dec 14, 2024This vulnerability allows unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when viewed. All WordPress sites...
Nov 26, 2024This vulnerability allows attackers to upload malicious files to DedeBIZ CMS through the admin interface, potentially leading to remote code execution...
Nov 20, 2024A file upload vulnerability in Laravel CMS v1.4.7 and earlier allows remote attackers to upload malicious PHP files (like shell.php) and execute arbit...
Nov 8, 2024This vulnerability allows remote attackers to execute arbitrary code on SourceCodester Purchase Order Management System v1.0 via the /admin?page=user ...
Oct 24, 2024This vulnerability allows attackers to upload arbitrary files to the moziloCMS admin interface, potentially leading to remote code execution. It affec...
Sep 10, 2024The Funnelforms Free WordPress plugin allows authenticated administrators to upload arbitrary files due to missing file type validation. This vulnerab...
Aug 28, 2024PublicCMS versions up to V4.0.202302.e contain an unrestricted file upload vulnerability in the template metadata management endpoint. This allows aut...
Aug 23, 2024This vulnerability allows authenticated administrators in Versa Director to upload malicious files disguised as PNG images through the favicon customi...
Aug 22, 2024Kashipara Hotel Management System v1.0 contains an unrestricted file upload vulnerability in the /admin/add_room_controller.php endpoint that allows r...
Aug 22, 2024About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free