CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,404)
This vulnerability allows attackers to upload malicious files to WordPress sites running the InstaWP Connect plugin, leading to remote code execution....
Apr 3, 2024This vulnerability allows authenticated remote attackers to write arbitrary files to Ivanti ITSM servers. Successful exploitation could lead to remote...
Mar 31, 2024This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Tourfic plugin, potentially leading to remote code execut...
Mar 19, 2024CVE-2024-2599 is a file upload restriction evasion vulnerability in AMSS++ version 4.31 that allows authenticated users to bypass security controls an...
Mar 18, 2024This vulnerability allows attackers to upload arbitrary files, including malicious scripts, to WordPress sites using the WP Media Folder plugin. It af...
Feb 26, 2024Suite CRM version 7.14.2 contains a Local File Inclusion (LFI) vulnerability that allows attackers to include and execute arbitrary PHP files from the...
Feb 20, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites running the WP Mail Log plugin. Attackers can upload ...
Dec 29, 2023This vulnerability allows attackers to upload arbitrary files, including malicious scripts, to WordPress sites using the Corsa theme. It affects all v...
Dec 20, 2023This vulnerability allows attackers to upload arbitrary files to WordPress sites using vulnerable versions of the AutomateWoo plugin for WooCommerce. ...
Dec 20, 2023This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Export Import Menus plugin. Attackers can upload maliciou...
Dec 20, 2023This vulnerability allows attackers to upload arbitrary files to WordPress sites running the Dropshipping & Affiliation with Amazon plugin. Attackers ...
Dec 20, 2023This vulnerability allows remote authenticated users to upload malicious ZIP archives that can execute arbitrary system commands with SYSTEM privilege...
Oct 17, 2023CVE-2022-3682 is a file permission validation vulnerability in Hitachi Energy SDM600 that allows authenticated attackers to upload specially crafted m...
Mar 28, 2023This vulnerability allows authenticated WordPress users with contributor-level permissions or higher to upload arbitrary files, including malicious PH...
Jan 1, 2021This vulnerability allows authenticated attackers to upload malicious ASPX files to Ivanti Endpoint Manager servers, leading to remote code execution....
Nov 12, 2020This is a critical remote code execution vulnerability in Microsoft Devices Pricing Program that allows attackers to execute arbitrary code on affecte...
Mar 5, 2026The Slider Future WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability ...
Feb 19, 2026The midi-Synth WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing validation in the 'export' AJAX action. This...
Feb 14, 2026Airleader Master versions 6.381 and prior have unrestricted file upload functionality on multiple webpages running with maximum privileges. This allow...
Feb 12, 2026This vulnerability allows attackers to upload malicious files to NTN Smart Panel systems, bypassing access controls. Attackers can execute arbitrary c...
Feb 12, 2026This vulnerability allows unauthenticated attackers to upload arbitrary PHP files to WordPress sites using the WPvivid Backup & Migration plugin, lead...
Feb 11, 2026FUXA v1.2.7 has an unauthenticated file upload vulnerability in the /api/upload endpoint that allows remote attackers to upload arbitrary files. This ...
Feb 3, 2026MediaCrush versions through 1.0.1 contain an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files of...
Feb 3, 2026A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without proper authentication, leading to stored cross-site scriptin...
Feb 2, 2026Computer Book Store 1.0 contains an unrestricted file upload vulnerability in admin_add.php that allows attackers to upload malicious files. This can ...
Jan 27, 2026CVE-2025-69565 is an unrestricted file upload vulnerability in code-projects Mobile Shop Management System 1.0 that allows attackers to upload malicio...
Jan 27, 2026The Kalrav AI Agent WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerabilit...
Jan 24, 2026This vulnerability allows unauthenticated attackers to upload malicious PHP files disguised as images to the Modern Image Gallery App v1.0. Successful...
Jan 23, 2026This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the vulnerable g-FFL Checkout plugin...
Jan 22, 2026This vulnerability allows attackers to upload arbitrary files, including web shells, to web servers running the Farost Energia WordPress theme. Attack...
Jan 22, 2026MeetingHub software from HAMASTAR Technology contains an unauthenticated arbitrary file upload vulnerability that allows remote attackers to upload ma...
Jan 22, 2026CVE-2025-14894 is an unauthenticated remote code execution vulnerability in Livewire Filemanager for Laravel applications. Attackers can upload malici...
Jan 16, 2026The Police Statistics Database System developed by Gotac contains an arbitrary file upload vulnerability that allows unauthenticated remote attackers ...
Jan 16, 2026This CVE describes a critical file upload vulnerability in Omnispace Agora Project that allows attackers to execute arbitrary code through the Imagick...
Jan 15, 2026CVE-2021-47819 is a critical file upload vulnerability in ProjeQtOr Project Management software that allows guest users to upload malicious PHP files ...
Jan 15, 2026CVE-2021-47753 is an unauthenticated file upload vulnerability in phpKF CMS that allows remote attackers to upload malicious PHP files disguised as PN...
Jan 15, 2026An arbitrary file upload vulnerability in Hubert Hub v2.0 allows attackers to upload malicious PDF files to execute arbitrary code on affected systems...
Jan 13, 2026This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Corpkit theme. It affects all Wo...
Jan 8, 2026This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the ContentStudio plugin. Attackers ...
Jan 8, 2026CVE-2024-27480 is an insecure file upload vulnerability in VvvebJs 1.7.2 that allows attackers to upload malicious files without proper validation. Th...
Dec 29, 2025VvvebJs 1.7.2 contains an unrestricted file upload vulnerability in save.php that allows attackers to upload arbitrary files, including malicious scri...
Dec 29, 2025A file upload vulnerability in MachSol MachPanel 8.0.32 allows attackers to upload malicious files and gain webshell access. This affects organization...
Dec 29, 2025CVE-2025-15228 is a critical arbitrary file upload vulnerability in WELLTEND TECHNOLOGY's BPMFlowWebkit software. Unauthenticated remote attackers can...
Dec 29, 2025WMPro software from Sunnet contains an unauthenticated arbitrary file upload vulnerability that allows remote attackers to upload malicious files (lik...
Dec 29, 2025CVE-2023-53980 is a critical remote code execution vulnerability in ProjectSend r1605 that allows attackers to upload malicious files with disguised e...
Dec 22, 2025The File Uploader for WooCommerce WordPress plugin allows unauthenticated attackers to upload arbitrary files to the Uploadcare service, which can the...
Dec 20, 2025This vulnerability allows attackers to upload malicious files to WordPress sites using the Contact Form 7 PDF, Google Sheet & Database plugin. Attacke...
Dec 18, 2025SitemagicCMS 4.4.3 contains an unrestricted file upload vulnerability that allows attackers to upload malicious PHP files, leading to remote code exec...
Dec 17, 2025CVE-2023-53922 is a critical remote code execution vulnerability in TinyWebGallery v2.5 that allows unauthenticated attackers to upload malicious PHP ...
Dec 17, 2025Soosyze 2.0.0 contains an unrestricted file upload vulnerability that allows attackers to upload HTML files containing PHP code. This enables remote c...
Dec 15, 2025About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free