CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,489
Total CVEs
745
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Phpgurukul 8
5 Apache 7
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,489)

CVE-2021-20022
7.2

CVE-2021-20022 is a post-authentication arbitrary file upload vulnerability in SonicWall Email Security. An authenticated attacker can upload maliciou...

Apr 9, 2021
CVE-2021-24155
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary files, including PHP files, through the Backup Guard plugin's imp...

Apr 5, 2021
CVE-2021-24145
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary PHP files disguised as CSV files in the Modern Events Calendar Li...

Mar 18, 2021
CVE-2021-24123
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary files, including PHP scripts, through the PowerPress plugin's pod...

Mar 18, 2021
CVE-2020-36079
7.2

Zenphoto CMS versions through 1.5.7 allow authenticated administrators to upload arbitrary files, including PHP web shells, leading to remote code exe...

Feb 26, 2021
CVE-2020-22643
7.2

Feehi CMS 2.1.0 contains an arbitrary file upload vulnerability that allows authenticated administrators to upload malicious files. This can lead to r...

Jan 26, 2021
CVE-2020-35656
7.2

This vulnerability in Jaws CMS allows authenticated administrators to upload and execute arbitrary PHP files, leading to remote code execution. It aff...

Dec 23, 2020
CVE-2020-29607
7.2

This vulnerability allows an authenticated admin user in Pluck CMS to bypass file upload restrictions, potentially uploading malicious files that coul...

Dec 16, 2020
CVE-2020-28072
7.2

CVE-2020-28072 is a remote code execution vulnerability in DourceCodester Alumni Management System 1.0. Authenticated attackers can upload malicious f...

Dec 15, 2020
CVE-2020-23520
7.2

CVE-2020-23520 is an authenticated file upload vulnerability in imcat 5.2 that allows attackers to upload malicious files and achieve remote code exec...

Dec 9, 2020
CVE-2020-28939
7.2

OpenClinic version 0.8.2 contains an insecure file upload vulnerability in medical/test_new.php that allows authenticated users with substantial privi...

Dec 3, 2020
CVE-2020-29441
7.2

This vulnerability allows unauthenticated attackers to upload arbitrary files to OutSystems Platform 10 instances. It affects organizations using OutS...

Nov 30, 2020
CVE-2020-28692
7.2

This vulnerability in Gila CMS 1.16.0 allows attackers to upload malicious PHP shell files to the temporary directory and execute them by abusing the ...

Nov 16, 2020
CVE-2020-26820
7.2

This vulnerability allows authenticated administrators in SAP NetWeaver AS JAVA to upload malicious files that enable remote code execution. Attackers...

Nov 10, 2020
CVE-2020-8260
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on Pulse Connect Secure VPN appliances by exploiting uncontrolled gzip ext...

Oct 28, 2020
CVE-2019-1888
7.2

This vulnerability allows authenticated administrators in Cisco Unified Contact Center Express to upload malicious files that execute arbitrary operat...

Sep 23, 2020
CVE-2020-25790
7.2

Typesetter CMS 5.x through 5.1 allows authenticated administrators to upload ZIP archives containing PHP files, which can then be executed on the serv...

Sep 19, 2020
CVE-2020-25287
7.2

CVE-2020-25287 is an arbitrary file write vulnerability in Pligg CMS that allows authenticated users to edit any file on the server through template e...

Sep 13, 2020
CVE-2020-24986
7.2

This vulnerability allows authenticated attackers to upload PHP files through Concrete5's File Manager by modifying site configuration. Successful exp...

Sep 4, 2020
CVE-2020-14008
7.2

This vulnerability allows an authenticated admin user in Zoho ManageEngine Applications Manager to upload a malicious JAR file to a specific location,...

Sep 4, 2020
CVE-2020-24948
7.2

This vulnerability allows authenticated WordPress administrators to upload arbitrary files through the Autoptimize plugin's AJAX interface, bypassing ...

Sep 3, 2020
CVE-2020-17452
7.2

This vulnerability allows authenticated administrators in flatCore CMS to upload and execute arbitrary PHP files, leading to remote code execution. It...

Aug 9, 2020
CVE-2025-54460
7.1

This vulnerability allows authenticated users with publication target creation/access privileges to upload and persist files that could be executed. I...

Aug 21, 2025
CVE-2024-25636
7.1

CVE-2024-25636 is a content-type validation vulnerability in Misskey that allows account takeover through ActivityPub protocol exploitation. Attackers...

Feb 19, 2024
CVE-2025-66837
6.8

A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to upload malicious PDF files that can execute arbitrary code on the server. Th...

Jan 7, 2026
CVE-2025-55810
6.8

This vulnerability allows physical attackers to execute arbitrary commands as root on Alaga Home Security WiFi Camera 3K devices by placing a speciall...

Nov 13, 2025
CVE-2025-49222
6.8

This vulnerability allows system administrators in Mattermost to upload non-attachment file types via shared channels, potentially placing files in ar...

Aug 21, 2025
CVE-2024-39752
6.8

IBM Analytics Content Hub versions 2.0-2.3 have a file upload vulnerability that allows attackers to upload malicious executable files. This could ena...

Jul 10, 2025
CVE-2024-8725
6.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to upload .css and .js files to arbitrary directories w...

Sep 26, 2024
CVE-2025-3125
6.7

An arbitrary file upload vulnerability in WSO2 products allows authenticated admin users to upload malicious files to server locations they control, p...

Nov 5, 2025
CVE-2025-30173
6.7

This CVE describes a file upload vulnerability in ABB's ASPECT, NEXUS, and MATRIX series products that allows attackers to upload malicious files if t...

May 22, 2025
CVE-2025-30169
6.7

This vulnerability allows attackers to upload and execute malicious PHP scripts in ASPECT systems if they obtain administrator credentials. It affects...

May 22, 2025
CVE-2025-39538
6.6

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the WP-Advanced-Search plugin. Attac...

Apr 16, 2025
CVE-2025-31577
6.6

This vulnerability allows attackers to upload arbitrary files, including web shells, to Appointify WordPress plugin servers. It affects all Appointify...

Mar 31, 2025
CVE-2024-49676
6.6

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable Custom Icons for Elem...

Oct 23, 2024
CVE-2025-69618
6.5

This vulnerability in Tarot, Astro & Healing v11.4.0 allows attackers to overwrite arbitrary files during the import process. Attackers could potentia...

Feb 4, 2026
CVE-2026-23704
6.5

This vulnerability allows non-administrative users to upload malicious files that can execute arbitrary scripts in administrators' browsers when acces...

Feb 4, 2026
CVE-2025-20375
6.5

This vulnerability allows authenticated administrators on Cisco Unified CCX systems to upload and execute arbitrary files through the web UI, potentia...

Nov 5, 2025
CVE-2025-20376
6.5

This vulnerability allows authenticated administrators in Cisco Unified CCX to upload and execute arbitrary files via the web UI, leading to remote co...

Nov 5, 2025
CVE-2025-43750
6.5

This vulnerability allows unauthenticated remote users (including guest users) to upload malicious files to Liferay Portal/DXP systems by bypassing fi...

Aug 20, 2025
CVE-2025-54757
6.5

PowerCMS versions before 6.7.1, 5.3.1, and 4.6.1 allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file up...

Jul 31, 2025
CVE-2024-41454
6.5

This vulnerability allows attackers to upload malicious PHP or HTML files through the login page logo upload function in Process Maker's pm4core-docke...

Jan 15, 2025
CVE-2024-34683
6.5

An authenticated attacker can upload malicious files to the SAP Document Builder service, which when accessed by a victim allows the attacker to acces...

Jun 11, 2024
CVE-2023-28652
6.5

This vulnerability allows authenticated users to upload malicious image files that can cause a denial-of-service condition. It affects industrial cont...

Mar 27, 2023
CVE-2025-55135
6.4

This vulnerability allows cross-site scripting (XSS) attacks via malicious SVG profile picture uploads in Agora Foundation's Agora software. Attackers...

Aug 7, 2025
CVE-2025-54962
6.4

This vulnerability allows authenticated users to upload arbitrary files (like .html or .svg) through the /edit-user endpoint in OpenPLC Runtime. These...

Aug 4, 2025
CVE-2025-51736
6.3

This CVE describes a file upload vulnerability in HCL Unica 12.0.0 that allows attackers to upload malicious files to the server. The vulnerability af...

Nov 28, 2025
CVE-2025-27714
6.3

This vulnerability allows attackers to upload arbitrary files through a specific endpoint, potentially leading to remote code execution and system com...

Aug 21, 2025
CVE-2024-47151
6.3

This CVE describes a file writing vulnerability in certain Honor products that could allow attackers to write arbitrary files to the system. If exploi...

Dec 26, 2024
CVE-2024-10420
6.3

This critical vulnerability in SourceCodester Attendance and Payroll System 1.0 allows remote attackers to upload arbitrary files via the /marimar/gue...

Oct 27, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,489 CVEs classified as CWE-434, with 745 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free