CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,399
Total CVEs
697
Critical
587
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,399)

CVE-2025-24775
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Made I.T. Forms plugin. Attacker...

Aug 14, 2025
CVE-2025-47452
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the WP VR plugin. Attackers can gain...

Jun 17, 2025
CVE-2025-46490
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the Crossword Compiler Puzzles WordPress p...

May 23, 2025
CVE-2025-39402
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable WPAMS plugin. Attacke...

May 19, 2025
CVE-2025-26872
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Eximius theme, potentially leading to complete system compr...

May 19, 2025
CVE-2025-46616
9.9

Quantum StorNext Web GUI API before version 7.2.4 contains a vulnerability that allows attackers to upload malicious files, potentially leading to arb...

Apr 25, 2025
CVE-2025-46264
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running vulnerable versions of the PowerPres...

Apr 24, 2025
CVE-2025-32682
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running MapSVG Lite. Attackers can achieve r...

Apr 17, 2025
CVE-2025-32652
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Solace Extra plugin. Attackers can execute arbitrary code, ...

Apr 17, 2025
CVE-2025-27282
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Theme File Duplicator plugin. Attackers can execute arbitra...

Apr 17, 2025
CVE-2025-32140
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the WP Remote Thumbnail plugin. Atta...

Apr 10, 2025
CVE-2024-10960
9.9

The Brizy Page Builder WordPress plugin allows authenticated users with Contributor-level access or higher to upload arbitrary files due to missing fi...

Feb 12, 2025
CVE-2024-57968
KEV EPSS 25.1% 9.9

This vulnerability in Advantive VeraCore allows authenticated remote users to upload files to unintended folders, potentially exposing sensitive files...

Feb 3, 2025
CVE-2025-23918
9.9

CVE-2025-23918 is an arbitrary file upload vulnerability in the Smallerik File Browser WordPress plugin that allows attackers to upload malicious file...

Jan 22, 2025
CVE-2025-0471
9.9

An unrestricted file upload vulnerability in PMB platform versions 4.0.10 and above allows attackers to upload malicious files and gain remote code ex...

Jan 16, 2025
CVE-2025-22782
9.9

This vulnerability allows attackers to upload malicious files to WordPress servers running the WR Price List Manager for WooCommerce plugin. Attackers...

Jan 15, 2025
CVE-2024-46479
9.9

Venki Supravizio BPM through version 18.0.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious fi...

Jan 13, 2025
CVE-2024-56057
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPLMS plugin. It affects all WordPre...

Dec 18, 2024
CVE-2024-56050
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the WPLMS plugin. Attackers can gain ful...

Dec 18, 2024
CVE-2024-56052
9.9

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress sites running vulnerable versions of...

Dec 18, 2024
CVE-2024-51548
9.9

CVE-2024-51548 is a dangerous unrestricted file upload vulnerability in ABB ASPECT, NEXUS, and MATRIX series products that allows attackers to upload ...

Dec 5, 2024
CVE-2024-11082
9.9

The Tumult Hype Animations WordPress plugin allows authenticated attackers with Author-level permissions or higher to upload arbitrary files due to mi...

Nov 28, 2024
CVE-2024-52429
9.9

This vulnerability in the WP Quick Setup WordPress plugin allows attackers to upload arbitrary files, including web shells, to the server. It affects ...

Nov 18, 2024
CVE-2024-52406
9.9

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the CSV to html plug...

Nov 16, 2024
CVE-2024-52408
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites running the vulnerable PushAssist plugin. Atta...

Nov 16, 2024
CVE-2024-52400
9.9

CVE-2024-52400 is an unrestricted file upload vulnerability in the Gallerio WordPress plugin that allows attackers to upload malicious files, includin...

Nov 16, 2024
CVE-2024-52404
9.9

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the CF7 Reply Manager plugin, potentially leading to remote cod...

Nov 16, 2024
CVE-2024-52369
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the KBucket WordPress plugin. Attackers ca...

Nov 14, 2024
CVE-2024-52384
9.9

This vulnerability allows attackers to upload malicious files (like web shells) to WordPress servers running the Sage AI plugin. It affects all WordPr...

Nov 14, 2024
CVE-2024-8614
9.9

The JobSearch WP Job Board WordPress plugin allows authenticated users with subscriber-level access or higher to upload arbitrary files due to missing...

Nov 6, 2024
CVE-2024-9307
9.9

The mFolio Lite WordPress plugin allows authenticated attackers with Author-level access or higher to upload malicious SVG or EXE files due to missing...

Nov 6, 2024
CVE-2024-50529
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Rudra Innovative Software Traini...

Nov 4, 2024
CVE-2024-50427
9.9

This vulnerability allows attackers to upload arbitrary files to WordPress sites using the SurveyJS plugin, potentially leading to remote code executi...

Oct 29, 2024
CVE-2024-50480
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable AZEXO Marketing Autom...

Oct 29, 2024
CVE-2024-49669
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the INK Official plugin. Attackers c...

Oct 23, 2024
CVE-2024-49652
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites running the vulnerable ReneeCussack 3D Work In...

Oct 23, 2024
CVE-2024-49658
9.9

This vulnerability allows unauthenticated attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable WooCo...

Oct 23, 2024
CVE-2024-49260
9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Limb Gallery plugin, potentially leading to remote code exe...

Oct 16, 2024
CVE-2024-48035
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable ACF Images Search And...

Oct 16, 2024
CVE-2024-48027
9.9

This vulnerability allows attackers to upload malicious files, including web shells, to WordPress servers running the External Featured Image from Bin...

Oct 16, 2024
CVE-2024-8463
9.9

This vulnerability allows authenticated users to bypass file upload restrictions in PHPGurukul Job Portal 1.0, potentially uploading malicious files t...

Sep 5, 2024
CVE-2024-45076
9.9

This vulnerability in IBM webMethods Integration 10.15 allows authenticated users to upload and execute arbitrary files on the underlying operating sy...

Sep 4, 2024
CVE-2024-43249
9.9

This vulnerability allows authenticated attackers to upload arbitrary files with dangerous extensions to WordPress sites running Bit Form Pro. Success...

Aug 19, 2024
CVE-2024-37418
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Church Admin plugin. Attackers c...

Jul 9, 2024
CVE-2024-37420
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the Zita Elementor Site Library plugin. ...

Jul 9, 2024
CVE-2024-5853
9.9

The Sirv WordPress plugin (versions up to 7.2.6) allows authenticated attackers with Contributor-level access or higher to upload arbitrary files due ...

Jun 19, 2024
CVE-2024-4306
9.9

CVE-2024-4306 is a critical unrestricted file upload vulnerability in HubBank version 1.0.2 that allows authenticated users to upload malicious PHP fi...

Apr 29, 2024
CVE-2023-31090
9.9

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites running the Unlimited Elements for Elementor p...

Apr 24, 2024
CVE-2024-32514
9.9

This vulnerability allows authenticated attackers to upload arbitrary files, including malicious scripts, to WordPress sites running the vulnerable WP...

Apr 17, 2024
CVE-2024-31280
9.9

CVE-2024-31280 is an arbitrary file upload vulnerability in the WordPress Church Admin plugin that allows attackers to upload malicious files to vulne...

Apr 7, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,399 CVEs classified as CWE-434, with 697 rated critical and 587 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free