CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,404
Total CVEs
697
Critical
592
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,404)

CVE-2025-66256
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to Mozart FM Transmitter devices via the patch_contents.php endpoint. At...

Nov 26, 2025
CVE-2025-66250
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to DB Electronica Telecomunicazioni's Mozart FM Transmitter devices via ...

Nov 26, 2025
CVE-2025-13595
9.8

The CIBELES AI WordPress plugin has an unauthenticated arbitrary file upload vulnerability that allows attackers to download GitHub repositories and o...

Nov 25, 2025
CVE-2025-11456
9.8

The ELEX WordPress HelpDesk plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to missing file type ...

Nov 21, 2025
CVE-2025-34328
9.8

This critical vulnerability allows unauthenticated remote attackers to upload arbitrary files and execute code as SYSTEM on AudioCodes Fax Server and ...

Nov 19, 2025
CVE-2025-34329
9.8

AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23 expose an unauthenticated backup upload endpoint that allows remote attac...

Nov 19, 2025
CVE-2025-12057
9.8

The WavePlayer WordPress plugin before version 3.8.0 contains an unauthenticated arbitrary file upload vulnerability that leads to remote code executi...

Nov 19, 2025
CVE-2025-63228
9.8

The Mozart FM Transmitter web management interface contains an unauthenticated file upload vulnerability that allows attackers to upload malicious fil...

Nov 18, 2025
CVE-2025-63994
9.8

An arbitrary file upload vulnerability in RichFilemanager v2.7.6 allows attackers to upload malicious files to the server, potentially leading to remo...

Nov 18, 2025
CVE-2025-63695
9.8

DzzOffice v2.3.7 and earlier contains an arbitrary file upload vulnerability in the UEditor component that allows attackers to upload malicious files ...

Nov 18, 2025
CVE-2025-41347
9.8

This vulnerability allows unauthenticated attackers to upload dangerous files (like webshells) to WinPlus Portal servers via a specific API endpoint. ...

Nov 18, 2025
CVE-2025-11170
9.8

The WPē§»č”Œå°‚ē”Øćƒ—ćƒ©ć‚°ć‚¤ćƒ³ for CPI WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validat...

Nov 11, 2025
CVE-2021-4462
EPSS 20.5% 9.8

CVE-2021-4462 is an unrestricted file upload vulnerability in Employee Records System version 1.0 that allows remote unauthenticated attackers to uplo...

Nov 10, 2025
CVE-2025-34299
EPSS 57.4% 9.8

CVE-2025-34299 is an unauthenticated arbitrary file upload vulnerability in Monsta FTP versions 2.11 and earlier. Attackers can exploit this by connec...

Nov 7, 2025
CVE-2025-12352
9.8

The Gravity Forms WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the copy_post_ima...

Nov 7, 2025
CVE-2025-20354
9.8

This critical vulnerability in Cisco Unified CCX allows unauthenticated remote attackers to upload arbitrary files and execute commands with root priv...

Nov 5, 2025
CVE-2025-12674
9.8

The KiotViet Sync WordPress plugin allows unauthenticated attackers to upload arbitrary files to affected servers due to missing file type validation....

Nov 5, 2025
CVE-2025-12682
9.8

The Easy Upload Files During Checkout WordPress plugin allows unauthenticated attackers to upload arbitrary JavaScript files due to missing file type ...

Nov 4, 2025
CVE-2025-6440
9.8

The WooCommerce Designer Pro plugin for WordPress has an unauthenticated arbitrary file upload vulnerability that allows attackers to upload malicious...

Oct 24, 2025
CVE-2025-11948
9.8

CVE-2025-11948 is an unauthenticated arbitrary file upload vulnerability in Excellent Infotek's Document Management System. Attackers can upload malic...

Oct 20, 2025
CVE-2025-11391
9.8

The PPOM – Product Addons & Custom Fields for WooCommerce WordPress plugin has an arbitrary file upload vulnerability in its image cropper functiona...

Oct 18, 2025
CVE-2023-28814
9.8

Hikvision iSecure Center software has an improper file upload vulnerability that allows attackers to upload malicious files to the server due to insuf...

Oct 17, 2025
CVE-2025-10041
9.8

The Flex QR Code Generator WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulne...

Oct 15, 2025
CVE-2025-6553
9.8

The Ovatheme Events Manager WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vuln...

Oct 11, 2025
CVE-2025-8120
9.8

CVE-2025-8120 is an unauthenticated remote code execution vulnerability in PAD CMS's photo upload functionality. An attacker can upload arbitrary file...

Sep 30, 2025
CVE-2025-7063
9.8

CVE-2025-7063 is an unauthenticated remote code execution vulnerability in PAD CMS's file upload functionality. Attackers can upload arbitrary files w...

Sep 30, 2025
CVE-2025-10412
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress servers running the Uni CPO plugin. Attackers can potential...

Sep 23, 2025
CVE-2025-34195
9.8

This vulnerability allows remote code execution on Windows systems running vulnerable versions of Vasion Print (formerly PrinterLogic). Attackers can ...

Sep 19, 2025
CVE-2025-9113
9.8

The Doccure WordPress theme allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability affects...

Sep 8, 2025
CVE-2025-54944
9.8

This vulnerability allows remote attackers to upload malicious files to SUNNET Corporate Training Management System, potentially leading to arbitrary ...

Aug 30, 2025
CVE-2025-53970
9.8

This critical vulnerability in SS1 Ver.16.0.0.10 and earlier allows remote unauthenticated attackers to upload arbitrary files and execute operating s...

Aug 28, 2025
CVE-2025-52353
9.8

This vulnerability allows authenticated attackers to upload malicious files containing PHP code to Badaso CMS, bypassing content-type validation. When...

Aug 26, 2025
CVE-2025-43766
9.8

This vulnerability allows attackers to upload unrestricted files through Liferay's style books component, which are then processed within the environm...

Aug 23, 2025
CVE-2025-7441
9.8

The StoryChief WordPress plugin has an unauthenticated arbitrary file upload vulnerability in its REST API endpoint. Attackers can upload malicious fi...

Aug 16, 2025
CVE-2025-6679
9.8

The Bit Form builder plugin for WordPress allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This affects...

Aug 15, 2025
CVE-2025-22470
9.8

This vulnerability allows attackers to upload malicious Lua script files to affected SATO CL4/6NX Plus printers and execute them with root privileges....

Aug 6, 2025
CVE-2025-52239
9.8

CVE-2025-52239 is an arbitrary file upload vulnerability in ZKEACMS v4.1 that allows attackers to upload malicious files and execute arbitrary code on...

Aug 4, 2025
CVE-2013-10040
EPSS 60.7% 9.8

CVE-2013-10040 is an unauthenticated arbitrary file upload vulnerability in ClipBucket versions 2.6 and earlier. Attackers can upload PHP scripts via ...

Jul 31, 2025
CVE-2025-7437
9.8

The Ebook Store WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability af...

Jul 24, 2025
CVE-2025-54448
9.8

This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, leading to code injection and potential remote code execu...

Jul 23, 2025
CVE-2025-54442
9.8

This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, which can lead to remote code execution. It affects all M...

Jul 23, 2025
CVE-2025-54444
9.8

This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, leading to code injection and potential remote code execu...

Jul 23, 2025
CVE-2025-54440
9.8

This vulnerability allows attackers to upload malicious files to Samsung MagicINFO 9 Server, which can lead to code execution on the server. It affect...

Jul 23, 2025
CVE-2012-10020
EPSS 65.6% 9.8

The FoxyPress WordPress plugin versions up to 0.4.2.1 allow unauthenticated attackers to upload arbitrary files due to missing file type validation in...

Jul 22, 2025
CVE-2025-44658
9.8

This vulnerability allows attackers to upload malicious scripts with non-.php extensions that the Netgear RAX30 router's PHP-FPM configuration incorre...

Jul 21, 2025
CVE-2015-10138
EPSS 64.2% 9.8

The Work The Flow File Upload WordPress plugin has an unauthenticated arbitrary file upload vulnerability due to missing file type validation. This al...

Jul 19, 2025
CVE-2015-10135
EPSS 61.7% 9.8

The WPshop 2 E-Commerce plugin for WordPress versions before 1.3.9.6 allows unauthenticated attackers to upload arbitrary files due to missing file ty...

Jul 19, 2025
CVE-2016-15043
EPSS 82.5% 9.8

The WP Mobile Detector WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the resize.p...

Jul 19, 2025
CVE-2012-10019
EPSS 64.6% 9.8

The Front End Editor WordPress plugin before version 2.3 allows unauthenticated attackers to upload arbitrary files due to missing file type validatio...

Jul 19, 2025
CVE-2025-46001
9.8

An arbitrary file upload vulnerability in Filemanager v2.3.0 allows attackers to upload malicious PHP files by bypassing the is_allowed_file_type() fu...

Jul 18, 2025

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free