CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,491
Total CVEs
747
Critical
629
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 21
2 Zohocorp 14
3 Ivanti 13
4 Apache 8
5 Phpgurukul 8
6 Netgear 7
7 Oretnom23 7
8 Sap 7
9 Cisco 7
10 Dedecms 7

All Unrestricted File Upload CVEs (1,491)

CVE-2024-47151
6.3

This CVE describes a file writing vulnerability in certain Honor products that could allow attackers to write arbitrary files to the system. If exploi...

Dec 26, 2024
CVE-2024-10420
6.3

This critical vulnerability in SourceCodester Attendance and Payroll System 1.0 allows remote attackers to upload arbitrary files via the /marimar/gue...

Oct 27, 2024
CVE-2024-10413
6.3

This critical vulnerability in SourceCodester Online Hotel Reservation System 1.0 allows attackers to upload arbitrary files without restrictions via ...

Oct 27, 2024
CVE-2024-10293
6.3

This critical vulnerability in ZZCMS 2023 allows remote attackers to upload arbitrary files without restrictions via the Ebak_SetGotoPak function. Att...

Oct 23, 2024
CVE-2024-10161
6.3

This critical vulnerability in PHPGurukul Boat Booking System 1.0 allows remote attackers to upload arbitrary files via the change-image.php component...

Oct 20, 2024
CVE-2024-8342
6.3

This critical vulnerability in SourceCodester Petshop Management System 1.0 allows attackers to upload arbitrary files via the /controllers/add_client...

Aug 30, 2024
CVE-2024-8338
6.3

This critical vulnerability in HFO4 shudong-share 2.4.7 allows remote attackers to upload arbitrary files without restrictions via the /includes/fileR...

Aug 30, 2024
CVE-2024-8294
6.3

This critical vulnerability in FeehiCMS allows remote attackers to upload arbitrary files without restrictions via the FriendlyLink[image] parameter. ...

Aug 29, 2024
CVE-2024-8089
6.3

This vulnerability allows remote attackers to upload arbitrary files to the SourceCodester E-Commerce System 1.0 via the photo parameter in the admin ...

Aug 23, 2024
CVE-2024-7944
6.3

This critical vulnerability in itsourcecode Laravel Property Management System 1.0 allows remote attackers to upload arbitrary files without restricti...

Aug 20, 2024
CVE-2024-7943
6.3

This critical vulnerability in itsourcecode Laravel Property Management System 1.0 allows remote attackers to upload arbitrary files without restricti...

Aug 20, 2024
CVE-2024-7906
6.3

This critical vulnerability in DedeBIZ 6.3.0 allows remote attackers to upload arbitrary files without restrictions via the get_mime_type function in ...

Aug 18, 2024
CVE-2024-7904
6.3

This critical vulnerability in DedeBIZ 6.3.0 allows remote attackers to upload arbitrary files without restrictions via the admin/file_manage_control....

Aug 18, 2024
CVE-2024-7506
6.3

This vulnerability allows remote attackers to upload arbitrary files to the Tailoring Management System 1.0 via the /setlogo.php endpoint. Attackers c...

Aug 6, 2024
CVE-2024-7500
6.3

CVE-2024-7500 is a critical unrestricted file upload vulnerability in itsourcecode Airline Reservation System 1.0. Attackers can remotely upload malic...

Aug 6, 2024
CVE-2024-7450
6.3

This vulnerability allows remote attackers to upload arbitrary files to the Placement Management System 1.0 via the /resume_upload.php endpoint. Attac...

Aug 4, 2024
CVE-2024-7329
6.3

This critical vulnerability in YouDianCMS 7 allows remote attackers to upload arbitrary files without restrictions via the /Public/ckeditor/plugins/mu...

Jul 31, 2024
CVE-2024-7189
6.3

This critical vulnerability in itsourcecode Online Food Ordering System 1.0 allows attackers to upload arbitrary files via the 'photo' parameter in ed...

Jul 29, 2024
CVE-2024-6948
6.3

This critical vulnerability in Gargaj wuhu's Slide Editor component allows remote attackers to upload arbitrary files via the newSlideFile parameter i...

Jul 21, 2024
CVE-2024-6801
6.3

This critical vulnerability in SourceCodester Online Student Management System 1.0 allows attackers to upload arbitrary files via the /add-students.ph...

Jul 17, 2024
CVE-2024-6083
6.3

This critical vulnerability in PHPVibe allows attackers to upload arbitrary files without restrictions via the /app/uploading/upload-mp3.php endpoint....

Jun 18, 2024
CVE-2024-5734
6.3

This vulnerability allows remote attackers to upload arbitrary files to itsourcecode Online Discussion Forum 1.0 via the /members/poster.php endpoint....

Jun 7, 2024
CVE-2024-5518
6.3

This critical vulnerability in itsourcecode Online Discussion Forum 1.0 allows remote attackers to upload arbitrary files via the change_profile_pictu...

May 30, 2024
CVE-2024-5049
6.3

This critical vulnerability in Codezips E-Commerce Site 1.0 allows remote attackers to upload arbitrary files via the profilepic parameter in admin/ed...

May 17, 2024
CVE-2024-4963
6.3

This critical vulnerability in D-Link DAR-7000-40 allows remote attackers to upload arbitrary files via the /url/url.php endpoint due to unrestricted ...

May 16, 2024
CVE-2024-4960
6.3

This critical vulnerability in D-Link DAR-7000-40 allows remote attackers to upload arbitrary files via the licenseauthorization.php interface, potent...

May 16, 2024
CVE-2024-4923
6.3

This critical vulnerability in Codezips E-Commerce Site 1.0 allows remote attackers to upload arbitrary files via the profilepic parameter in admin/ad...

May 16, 2024
CVE-2024-33752
6.3

This vulnerability allows remote attackers to upload arbitrary files to emlog Pro installations, potentially leading to remote code execution. Attacke...

May 6, 2024
CVE-2024-4500
6.3

This critical vulnerability in SourceCodester Prison Management System 1.0 allows attackers to upload arbitrary files via the /Employee/edit-photo.php...

May 5, 2024
CVE-2023-1561
6.3

This critical vulnerability in Simple Online Hotel Reservation System 1.0 allows attackers to upload arbitrary files without restrictions via the add_...

Mar 22, 2023
CVE-2023-1558
6.3

This critical vulnerability in Simple and Beautiful Shopping Cart System 1.0 allows attackers to upload arbitrary files without restrictions via uploa...

Mar 22, 2023
CVE-2025-14842
6.1

The Drag and Drop Multiple File Upload plugin for Contact Form 7 in WordPress allows unauthenticated attackers to upload malicious .phar or .svg files...

Jan 7, 2026
CVE-2024-9648
6.1

The WP ULike Pro WordPress plugin allows unauthenticated attackers to upload malicious files with dangerous extensions like .php2, .phar, and .svg due...

Aug 28, 2025
CVE-2024-5278
6.1

This vulnerability allows attackers to upload malicious files to the gaizhenbiao/chuanhuchatgpt application due to insufficient file validation. Attac...

Jun 6, 2024
CVE-2025-67706
5.6

ArcGIS Server versions 11.5 and earlier on Windows and Linux contain a file upload vulnerability where remote attackers can upload arbitrary files. Ho...

Dec 31, 2025
CVE-2025-67707
5.6

ArcGIS Server versions 11.5 and earlier on Windows and Linux contain a file upload vulnerability that allows remote attackers to upload arbitrary file...

Dec 31, 2025
CVE-2025-48953
5.5

This vulnerability allows attackers to upload files with disallowed extensions in Umbraco CMS by manipulating API requests. It affects Umbraco install...

Jun 3, 2025
CVE-2025-1500
5.5

This vulnerability in IBM Maximo Application Suite 9.0 allows authenticated users to upload files with dangerous extensions that could be executed by ...

Apr 5, 2025
CVE-2024-44220
5.5

A memory handling vulnerability in macOS video file parsing allows attackers to cause system crashes by tricking users into opening malicious video fi...

Dec 12, 2024
CVE-2024-25020
5.5

IBM Cognos Controller versions 11.0.0 and 11.0.1 allow unrestricted file uploads in the Journal entry page, enabling attackers to upload malicious exe...

Dec 3, 2024
CVE-2026-24034
5.4

Horilla HRMS versions before 1.5.0 contain a cross-site scripting vulnerability in the profile photo upload functionality. Attackers can upload malici...

Jan 22, 2026
CVE-2021-47783
5.4

This vulnerability allows authenticated attackers to upload malicious SVG files containing JavaScript through Phpwcms's multiple file upload feature. ...

Jan 16, 2026
CVE-2023-53876
5.4

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files containing stored cross-site script...

Dec 15, 2025
CVE-2024-11390
5.4

This vulnerability allows attackers to upload malicious HTML/JavaScript files through Kibana's Synthetics app, leading to cross-site scripting (XSS) a...

May 1, 2025
CVE-2024-10584
5.4

The DirectoryPress WordPress plugin is vulnerable to stored XSS via SVG file uploads due to insufficient input sanitization. Authenticated attackers w...

Dec 24, 2024
CVE-2024-12042
5.4

The MStore API WordPress plugin has a stored XSS vulnerability in profile picture upload functionality. Authenticated attackers with subscriber-level ...

Dec 13, 2024
CVE-2025-66908
5.3

This vulnerability allows attackers to upload arbitrary files including executables, scripts, or web shells by bypassing file type validation in Turms...

Dec 19, 2025
CVE-2025-34330
5.3

This vulnerability allows unauthenticated remote attackers to upload files to AudioCodes Fax Server and Auto-Attendant IVR appliances via an unprotect...

Nov 19, 2025
CVE-2025-46078
5.3

HuoCMS V3.5.1 and earlier contains an unrestricted file upload vulnerability that allows attackers to upload malicious files to the server. This can l...

May 29, 2025
CVE-2024-51991
4.9

This vulnerability allows authenticated administrators in October CMS to bypass SVG file sanitization by uploading files with permitted extensions (li...

May 5, 2025

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,491 CVEs classified as CWE-434, with 747 rated critical and 629 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free