CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,485)
This vulnerability allows authenticated attackers with administrator-level WordPress access to upload arbitrary files with double extensions, potentia...
Aug 20, 2024The CRM Perks Forms WordPress plugin allows authenticated administrators to upload arbitrary files due to insufficient validation in the 'handle_uploa...
Aug 6, 2024This vulnerability allows attackers to upload malicious files to Webkul Qloapps v1.6.0.0, potentially leading to remote code execution. Any organizati...
Jul 25, 2024The Redux Framework WordPress plugin versions 4.4.12 to 4.4.17 allow unauthenticated attackers to upload JSON files due to missing authorization check...
Jul 23, 2024The Bit Form WordPress plugin allows authenticated attackers with administrator permissions to upload arbitrary files due to missing file type validat...
Jul 9, 2024This vulnerability in CHANGING Mobile One Time Password allows remote attackers with administrator privileges to upload malicious files through a hidd...
Jul 1, 2024This vulnerability in ASUS Download Master allows authenticated administrators to upload arbitrary files to any location on the system due to improper...
Jun 14, 2024This vulnerability allows high-privilege attackers to upload malicious files to Adobe Commerce systems, potentially leading to arbitrary code executio...
Jun 13, 2024This vulnerability allows authenticated privileged users in Ivanti Avalanche to upload arbitrary files, leading to remote code execution with SYSTEM p...
May 31, 2024This vulnerability in Triangle MicroWorks SCADA Data Gateway allows authenticated remote attackers to bypass authentication and upload arbitrary files...
May 3, 2024CVE-2020-22539 is an arbitrary file upload vulnerability in Codoforum v4.9's Add Category function, allowing attackers to upload malicious files that ...
Apr 15, 2024This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Moove Agency Import XML and RSS Feeds plugin. Attackers c...
Apr 7, 2024The BookingPress WordPress plugin allows authenticated administrators to upload arbitrary files due to insufficient filename validation. This vulnerab...
Apr 4, 2024This vulnerability allows attackers to upload arbitrary files to WordPress sites using the Theme Editor plugin. It affects all WordPress installations...
Mar 26, 2024This vulnerability allows authenticated WordPress users to upload arbitrary files, including malicious scripts, to affected websites. It affects the T...
Mar 26, 2024This vulnerability in phpMyFAQ allows attackers to upload malicious PHP files by manipulating Content-type and lang parameters during category image u...
Mar 25, 2024This vulnerability allows attackers to upload arbitrary files to WordPress sites using the Icons Font Loader plugin. It affects all WordPress installa...
Feb 26, 2024CVE-2024-22426 is an unauthenticated remote OS command injection vulnerability in Dell RecoverPoint for Virtual Machines. An attacker can execute arbi...
Feb 16, 2024The EditorsKit WordPress plugin has an arbitrary file upload vulnerability in versions up to 1.40.3. Authenticated attackers with administrator privil...
Feb 5, 2024This vulnerability allows authenticated attackers to upload malicious .phtml files to Schlix CMS, leading to remote code execution and potential data ...
Jan 31, 2024CVE-2024-24399 is an arbitrary file upload vulnerability in LEPTON CMS v7.0.0 that allows authenticated attackers to upload PHP files to the languages...
Jan 25, 2024The Theme Demo Import WordPress plugin before version 1.1.1 contains an unrestricted file upload vulnerability. High-privilege users (administrators) ...
Jan 16, 2024This vulnerability in PMB v7.4.8 allows remote attackers to upload malicious PHP files through the start_import.php endpoint, leading to arbitrary cod...
Jan 11, 2024The Export and Import Users and Customers WordPress plugin up to version 2.4.8 has insufficient file type validation in the upload_import_file functio...
Jan 11, 2024This vulnerability allows high-privileged WordPress users (like administrators) to upload arbitrary files including web shells to the server through t...
Jan 8, 2024This vulnerability allows attackers who steal the AdminToken cookie to upload malicious crontab files to GL.iNet devices, leading to arbitrary code ex...
Jan 3, 2024The E2Pdf WordPress plugin has an arbitrary file upload vulnerability in versions up to 1.20.25 due to insufficient file type validation. This allows ...
Dec 15, 2023The BookingPress WordPress plugin up to version 1.0.76 contains an arbitrary file upload vulnerability in the 'bookingpress_process_upload' function d...
Nov 28, 2023CVE-2023-46004 is an arbitrary file upload vulnerability in Sourcecodester Best Courier Management System 1.0 that allows attackers to upload maliciou...
Oct 18, 2023This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Verify Privilege On-Premises systems by sending...
Oct 17, 2023This vulnerability in Welcart e-Commerce allows users with editor or higher privileges to upload arbitrary files to unauthorized directories. This cou...
Sep 27, 2023This vulnerability in SiberianCMS allows administrators to upload dangerous file types without proper validation. Attackers with admin access could up...
Sep 27, 2023This vulnerability allows remote attackers to execute arbitrary code on PerfreeBlog installations by uploading malicious plugin files through the admi...
Aug 28, 2023This vulnerability allows remote attackers to upload malicious PHP files to an Online Travel Agency System v1.0 via the employee_insert.php endpoint. ...
Aug 17, 2023This vulnerability allows attackers to upload arbitrary PHP files to WBCE CMS through the /languages/install.php component, leading to remote code exe...
Aug 3, 2023This vulnerability allows authenticated attackers to upload arbitrary files to Veritas InfoScale Operations Manager servers, which can then be execute...
Jul 17, 2023CVE-2023-3692 is an unrestricted file upload vulnerability in Admidio that allows attackers to upload malicious files to the server. This affects Admi...
Jul 16, 2023This vulnerability in WL-WN531AX2 routers allows attackers with administrative access to upload arbitrary files and execute operating system commands ...
Jun 30, 2023CVE-2023-34736 is an arbitrary file upload vulnerability in Guantang Equipment Management System version 4.12 that allows attackers to upload maliciou...
Jun 28, 2023This vulnerability allows remote attackers to upload malicious files through the theme.php file in Pluck CMS, potentially leading to arbitrary code ex...
Jun 20, 2023CVE-2023-33569 allows remote attackers to execute arbitrary code on Faculty Evaluation System v1.0 installations via the ip/eval/ajax.php?action=updat...
Jun 6, 2023The ZYREX POPUP WordPress plugin through version 1.0 allows administrators to upload arbitrary files without proper validation, bypassing file system ...
May 2, 2023This vulnerability allows attackers to bypass Drupal's filename sanitization when .htaccess files are explicitly allowed for upload, potentially leadi...
Apr 26, 2023This vulnerability allows remote authenticated attackers with high privileges to execute arbitrary commands on Meinberg LTOS systems by exploiting imp...
Apr 24, 2023This vulnerability allows attackers with administrator permissions to upload malicious files disguised as images, leading to remote code execution on ...
Apr 5, 2023This vulnerability allows attackers to upload arbitrary PHP files to the Dynamic Transaction Queuing System v1.0 through the /admin/ajax.php endpoint....
Apr 5, 2023Pluck CMS has an authenticated remote code execution vulnerability in its albums module. Attackers with administrator credentials can upload malicious...
Mar 27, 2023This vulnerability allows attackers to upload malicious .phtml files to Jizhicms administration panels, leading to remote code execution. Any organiza...
Mar 15, 2023CVE-2022-40924 is an arbitrary file upload vulnerability in Zoo Management System v1.0 that allows attackers to upload malicious files through the ani...
Sep 26, 2022Barangay Management System v1.0 contains an arbitrary file upload vulnerability in the resident module editing function. Attackers can upload maliciou...
Jul 19, 2022About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free