CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,485
Total CVEs
741
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,485)

CVE-2022-1565
7.2

The WP All Import WordPress plugin up to version 3.6.7 contains a vulnerability that allows authenticated attackers with administrator-level permissio...

Jul 18, 2022
CVE-2022-31854
7.2

CVE-2022-31854 is an arbitrary file upload vulnerability in Codoforum v5.1 that allows authenticated administrators to upload malicious files via the ...

Jul 7, 2022
CVE-2021-37770
7.2

Nucleus CMS v3.71 has a file upload vulnerability that allows attackers to bypass .htaccess restrictions and upload malicious files disguised as image...

Jun 30, 2022
CVE-2022-1939
7.2

The Allow svg files WordPress plugin before version 1.1 has improper file upload validation, allowing administrators to upload PHP files even when fil...

Jun 20, 2022
CVE-2022-0863
7.2

This vulnerability allows high-privileged WordPress users (like administrators) to upload malicious ZIP files containing PHP code through the WP SVG I...

Jun 13, 2022
CVE-2022-30860
7.2

CVE-2022-30860 allows remote attackers to execute arbitrary code on FUDforum installations through the file upload feature in the admin control panel....

Jun 6, 2022
CVE-2022-29651
7.2

This vulnerability allows attackers to upload arbitrary PHP files through the Select Image function in Online Food Ordering System v1.0, leading to re...

May 25, 2022
CVE-2021-41938
7.2

ShopXO CMS 2.2.0 contains an arbitrary file upload vulnerability in three locations within the management interface. This allows authenticated attacke...

May 19, 2022
CVE-2022-30007
7.2

GXCMS V1.5 has a file upload vulnerability in the template management page that allows authenticated attackers to upload malicious PHP files. This can...

May 17, 2022
CVE-2022-1409
7.2

This vulnerability allows authenticated administrators in the VikBooking WordPress plugin to upload PHP files disguised as images, potentially leading...

May 16, 2022
CVE-2021-25119
7.2

The AGIL WordPress plugin through version 1.0 has an unrestricted file upload vulnerability that allows authenticated administrators to upload arbitra...

May 16, 2022
CVE-2022-29318
7.2

This vulnerability allows attackers to upload malicious PHP files through the New Entry module in Car Rental Management System v1.0, leading to remote...

May 11, 2022
CVE-2022-29001
7.2

SpringBootMovie versions 1.2 and earlier contain an arbitrary file upload vulnerability due to insufficient filtering of uploaded file suffixes. This ...

May 3, 2022
CVE-2022-1273
7.2

The Import WP WordPress plugin before version 2.4.6 contains an arbitrary file upload vulnerability that allows authenticated administrators to upload...

May 2, 2022
CVE-2022-1008
7.2

This vulnerability allows WordPress administrators to upload arbitrary files, including PHP scripts, through the One Click Demo Import plugin. It bypa...

Apr 11, 2022
CVE-2022-26607
7.2

This CVE describes a remote code execution vulnerability in baigo CMS v3.0-alpha-2 that allows attackers to upload malicious PHP files and execute arb...

Apr 6, 2022
CVE-2020-28062
7.2

This vulnerability allows remote attackers to execute arbitrary code on HisiPHP 2.0.11 systems through specially crafted packets that bypass access co...

Apr 4, 2022
CVE-2022-0537
7.2

This vulnerability in the MapPress Maps for WordPress plugin allows authenticated administrators to bypass WordPress security settings and upload arbi...

Apr 4, 2022
CVE-2022-23155
7.2

Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability that allows authenticated admin users to uploa...

Apr 1, 2022
CVE-2021-43098
7.2

This CVE describes an unrestricted file upload vulnerability in bbs v5.3 through the QuestionManageAction.java component. Attackers can upload malicio...

Mar 28, 2022
CVE-2021-43100
7.2

This vulnerability allows remote attackers to upload malicious files to bbs 5.3 through the TopicManageAction.java component, potentially leading to a...

Mar 28, 2022
CVE-2021-43102
7.2

This vulnerability allows remote attackers to upload malicious files through the HelpManageAction.java component in bbs 5.3, potentially leading to ar...

Mar 28, 2022
CVE-2022-1034
7.2

CVE-2022-1034 is an unrestricted file upload vulnerability in ShowDoc v2.10.3 that allows attackers to upload malicious files without proper validatio...

Mar 22, 2022
CVE-2022-26965
7.2

This vulnerability allows authenticated admin users in Pluck CMS 4.7.16 to upload malicious theme files through the theme installation functionality, ...

Mar 18, 2022
CVE-2021-42171
7.2

Zenario CMS 9.0.54156 has an unrestricted file upload vulnerability that allows attackers to upload malicious files like web shells. This enables remo...

Mar 14, 2022
CVE-2022-0440
7.2

This vulnerability in the Catch Themes Demo Import WordPress plugin allows high-privilege administrators to upload arbitrary PHP files, leading to rem...

Mar 7, 2022
CVE-2021-24216
7.2

This vulnerability in the All-in-One WP Migration WordPress plugin allows administrators to upload PHP files without proper file extension validation....

Mar 7, 2022
CVE-2022-23906
7.2

CMS Made Simple v2.2.15 contains a remote command execution vulnerability in the upload avatar function. Attackers can execute arbitrary commands on t...

Feb 28, 2022
CVE-2022-26149
7.2

CVE-2022-26149 allows remote authenticated administrators in MODX Revolution to execute arbitrary code by uploading executable files. This occurs beca...

Feb 26, 2022
CVE-2022-23043
7.2

CVE-2022-23043 is an unrestricted file upload vulnerability in Zenario CMS that allows authenticated admin users to bypass file upload restrictions by...

Feb 24, 2022
CVE-2022-23048
7.2

This vulnerability allows authenticated admin users in Exponent CMS to upload malicious ZIP files containing PHP scripts, which are then extracted to ...

Feb 9, 2022
CVE-2021-46115
7.2

CVE-2021-46115 is a remote code execution vulnerability in JPress 4.2.0 that allows authenticated attackers with admin panel access to upload maliciou...

Jan 26, 2022
CVE-2021-46079
7.2

An Unrestricted File Upload vulnerability in Vehicle Service Management System 1.0 allows remote attackers to upload malicious files containing HTML i...

Jan 6, 2022
CVE-2021-41675
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on Sourcecodester E-Negosyo System 1.0 servers. Attackers can upload malic...

Oct 29, 2021
CVE-2021-39352
7.2

This vulnerability allows attackers with administrative privileges in WordPress to upload malicious files through the Catch Themes Demo Import plugin'...

Oct 21, 2021
CVE-2021-40188
7.2

CVE-2021-40188 is an arbitrary file upload vulnerability in PHPFusion's admin panel File Manager that allows attackers to upload malicious PHP files w...

Oct 11, 2021
CVE-2021-24663
7.2

The Simple Schools Staff Directory WordPress plugin through version 1.1 contains an unrestricted file upload vulnerability that allows authenticated a...

Sep 20, 2021
CVE-2020-21483
7.2

CVE-2020-21483 is an arbitrary file upload vulnerability in Jizhicms v1.5 that allows attackers to upload malicious files disguised as .jpg images, wh...

Sep 15, 2021
CVE-2020-21481
7.2

CVE-2020-21481 is an arbitrary file upload vulnerability in RGCMS v1.06 that allows attackers to upload malicious .txt files that can later be renamed...

Sep 15, 2021
CVE-2021-39608
7.2

This vulnerability allows remote attackers to execute arbitrary PHP code on FlatCore-CMS 2.0.7 systems via the upload addon plugin. Attackers can achi...

Aug 23, 2021
CVE-2020-18886
7.2

This vulnerability allows remote attackers to upload arbitrary files to PHPMyWind v5.6 systems via the admin/upload_file_do.php component. Attackers c...

Aug 20, 2021
CVE-2021-22937
7.2

This vulnerability allows authenticated administrators on Pulse Connect Secure appliances to write arbitrary files by uploading a maliciously crafted ...

Aug 16, 2021
CVE-2020-18462
7.2

AikCms v2.0.0 contains an unauthenticated file upload vulnerability in poster_edit.php that allows attackers to upload arbitrary files without validat...

Aug 12, 2021
CVE-2021-24248
7.2

This vulnerability allows authenticated WordPress administrators to upload malicious PHP files through the Business Directory Plugin's import function...

May 6, 2021
CVE-2021-24252
7.2

The Event Banner WordPress plugin through version 1.3 has an unrestricted file upload vulnerability that allows authenticated admin users to upload ar...

May 6, 2021
CVE-2021-24254
7.2

The College Publisher Import WordPress plugin through version 0.1 allows authenticated administrators to upload arbitrary files including PHP scripts,...

May 6, 2021
CVE-2021-20022
7.2

CVE-2021-20022 is a post-authentication arbitrary file upload vulnerability in SonicWall Email Security. An authenticated attacker can upload maliciou...

Apr 9, 2021
CVE-2021-24155
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary files, including PHP files, through the Backup Guard plugin's imp...

Apr 5, 2021
CVE-2021-24145
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary PHP files disguised as CSV files in the Modern Events Calendar Li...

Mar 18, 2021
CVE-2021-24123
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary files, including PHP scripts, through the PowerPress plugin's pod...

Mar 18, 2021

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,485 CVEs classified as CWE-434, with 741 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free