CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,404)
This vulnerability allows unauthenticated attackers to upload arbitrary files to Mozart FM Transmitter devices via the patch_contents.php endpoint. At...
Nov 26, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files to DB Electronica Telecomunicazioni's Mozart FM Transmitter devices via ...
Nov 26, 2025The CIBELES AI WordPress plugin has an unauthenticated arbitrary file upload vulnerability that allows attackers to download GitHub repositories and o...
Nov 25, 2025The ELEX WordPress HelpDesk plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to missing file type ...
Nov 21, 2025This critical vulnerability allows unauthenticated remote attackers to upload arbitrary files and execute code as SYSTEM on AudioCodes Fax Server and ...
Nov 19, 2025AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23 expose an unauthenticated backup upload endpoint that allows remote attac...
Nov 19, 2025The WavePlayer WordPress plugin before version 3.8.0 contains an unauthenticated arbitrary file upload vulnerability that leads to remote code executi...
Nov 19, 2025The Mozart FM Transmitter web management interface contains an unauthenticated file upload vulnerability that allows attackers to upload malicious fil...
Nov 18, 2025An arbitrary file upload vulnerability in RichFilemanager v2.7.6 allows attackers to upload malicious files to the server, potentially leading to remo...
Nov 18, 2025DzzOffice v2.3.7 and earlier contains an arbitrary file upload vulnerability in the UEditor component that allows attackers to upload malicious files ...
Nov 18, 2025This vulnerability allows unauthenticated attackers to upload dangerous files (like webshells) to WinPlus Portal servers via a specific API endpoint. ...
Nov 18, 2025The WPē§»č”å°ēØćć©ć°ć¤ć³ for CPI WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validat...
Nov 11, 2025CVE-2021-4462 is an unrestricted file upload vulnerability in Employee Records System version 1.0 that allows remote unauthenticated attackers to uplo...
Nov 10, 2025CVE-2025-34299 is an unauthenticated arbitrary file upload vulnerability in Monsta FTP versions 2.11 and earlier. Attackers can exploit this by connec...
Nov 7, 2025The Gravity Forms WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the copy_post_ima...
Nov 7, 2025This critical vulnerability in Cisco Unified CCX allows unauthenticated remote attackers to upload arbitrary files and execute commands with root priv...
Nov 5, 2025The KiotViet Sync WordPress plugin allows unauthenticated attackers to upload arbitrary files to affected servers due to missing file type validation....
Nov 5, 2025The Easy Upload Files During Checkout WordPress plugin allows unauthenticated attackers to upload arbitrary JavaScript files due to missing file type ...
Nov 4, 2025The WooCommerce Designer Pro plugin for WordPress has an unauthenticated arbitrary file upload vulnerability that allows attackers to upload malicious...
Oct 24, 2025CVE-2025-11948 is an unauthenticated arbitrary file upload vulnerability in Excellent Infotek's Document Management System. Attackers can upload malic...
Oct 20, 2025The PPOM ā Product Addons & Custom Fields for WooCommerce WordPress plugin has an arbitrary file upload vulnerability in its image cropper functiona...
Oct 18, 2025Hikvision iSecure Center software has an improper file upload vulnerability that allows attackers to upload malicious files to the server due to insuf...
Oct 17, 2025The Flex QR Code Generator WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulne...
Oct 15, 2025The Ovatheme Events Manager WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vuln...
Oct 11, 2025CVE-2025-8120 is an unauthenticated remote code execution vulnerability in PAD CMS's photo upload functionality. An attacker can upload arbitrary file...
Sep 30, 2025CVE-2025-7063 is an unauthenticated remote code execution vulnerability in PAD CMS's file upload functionality. Attackers can upload arbitrary files w...
Sep 30, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress servers running the Uni CPO plugin. Attackers can potential...
Sep 23, 2025This vulnerability allows remote code execution on Windows systems running vulnerable versions of Vasion Print (formerly PrinterLogic). Attackers can ...
Sep 19, 2025The Doccure WordPress theme allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability affects...
Sep 8, 2025This vulnerability allows remote attackers to upload malicious files to SUNNET Corporate Training Management System, potentially leading to arbitrary ...
Aug 30, 2025This critical vulnerability in SS1 Ver.16.0.0.10 and earlier allows remote unauthenticated attackers to upload arbitrary files and execute operating s...
Aug 28, 2025This vulnerability allows authenticated attackers to upload malicious files containing PHP code to Badaso CMS, bypassing content-type validation. When...
Aug 26, 2025This vulnerability allows attackers to upload unrestricted files through Liferay's style books component, which are then processed within the environm...
Aug 23, 2025The StoryChief WordPress plugin has an unauthenticated arbitrary file upload vulnerability in its REST API endpoint. Attackers can upload malicious fi...
Aug 16, 2025The Bit Form builder plugin for WordPress allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This affects...
Aug 15, 2025This vulnerability allows attackers to upload malicious Lua script files to affected SATO CL4/6NX Plus printers and execute them with root privileges....
Aug 6, 2025CVE-2025-52239 is an arbitrary file upload vulnerability in ZKEACMS v4.1 that allows attackers to upload malicious files and execute arbitrary code on...
Aug 4, 2025CVE-2013-10040 is an unauthenticated arbitrary file upload vulnerability in ClipBucket versions 2.6 and earlier. Attackers can upload PHP scripts via ...
Jul 31, 2025The Ebook Store WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability af...
Jul 24, 2025This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, leading to code injection and potential remote code execu...
Jul 23, 2025This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, which can lead to remote code execution. It affects all M...
Jul 23, 2025This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, leading to code injection and potential remote code execu...
Jul 23, 2025This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, which can lead to code execution on the server. It affect...
Jul 23, 2025The FoxyPress WordPress plugin versions up to 0.4.2.1 allow unauthenticated attackers to upload arbitrary files due to missing file type validation in...
Jul 22, 2025This vulnerability allows attackers to upload malicious scripts with non-.php extensions that the Netgear RAX30 router's PHP-FPM configuration incorre...
Jul 21, 2025The Work The Flow File Upload WordPress plugin has an unauthenticated arbitrary file upload vulnerability due to missing file type validation. This al...
Jul 19, 2025The WPshop 2 E-Commerce plugin for WordPress versions before 1.3.9.6 allows unauthenticated attackers to upload arbitrary files due to missing file ty...
Jul 19, 2025The WP Mobile Detector WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the resize.p...
Jul 19, 2025The Front End Editor WordPress plugin before version 2.3 allows unauthenticated attackers to upload arbitrary files due to missing file type validatio...
Jul 19, 2025An arbitrary file upload vulnerability in Filemanager v2.3.0 allows attackers to upload malicious PHP files by bypassing the is_allowed_file_type() fu...
Jul 18, 2025About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free