CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,404)
This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the WooCommerce Refund And Exchange plugin due ...
Jul 18, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the HT Contact Form Widget plugin due to missin...
Jul 15, 2025The AIT CSV import/export WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulner...
Jul 12, 2025This vulnerability allows unauthenticated attackers to rename uploaded PHP files with .png extensions to .php extensions, enabling remote code executi...
Jul 12, 2025The WPBookit WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability can l...
Jul 12, 2025This vulnerability allows unauthenticated remote attackers to upload arbitrary files to Marvell QConvergeConsole servers, leading to remote code execu...
Jul 7, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress servers running vulnerable versions of the Drag and Drop Mu...
Jul 2, 2025This vulnerability in FusionForge's Apache configuration allows remote code execution by enabling attackers to execute arbitrary scripts uploaded to S...
Jun 26, 2025This vulnerability allows remote attackers to upload malicious files to the Soar Cloud HRD Human Resource Management System, which can lead to arbitra...
Jun 6, 2025FreeScout versions before 1.8.179 have an unrestricted file upload vulnerability that allows attackers to upload malicious PHP files (.phtml, .phar ex...
May 29, 2025The Crawlomatic WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability af...
May 17, 2025Emlog Pro versions before 2.5.10 contain a critical file upload vulnerability in the store.php component that fails to properly validate remotely down...
May 15, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the ηΎεΊ¦η«ιΏSEOει plugin. Attackers can...
May 15, 2025The Envolve Plugin for WordPress allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability af...
May 9, 2025Grocery-CMS-PHP-Restful-API v1.3 has an unrestricted file upload vulnerability in the /admin/add-category.php endpoint that allows attackers to upload...
May 8, 2025An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to upload malicious files that can lead to remote code...
Apr 21, 2025The Smart Product Review WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnera...
Apr 19, 2025The AIHub WordPress theme allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the generate_image functio...
Apr 19, 2025This vulnerability allows attackers to upload arbitrary PHP files to Sourcecodester Online ID Generator System 1.0, leading to remote code execution. ...
Apr 16, 2025The Front End Users WordPress plugin allows unauthenticated attackers to upload arbitrary files through registration forms due to missing file type va...
Apr 2, 2025An arbitrary file upload vulnerability in Mart Developers iBanking v2.0.0 allows authenticated attackers to upload malicious PHP files through the Cli...
Mar 20, 2025This vulnerability allows attackers to read and write arbitrary files on servers running composiohq/composio version 0.4.3 due to improper path valida...
Mar 20, 2025This vulnerability in eosphoros-ai/db-gpt allows attackers to execute arbitrary SQL queries via an unprotected web API endpoint, leading to arbitrary ...
Mar 20, 2025The File Away WordPress plugin allows unauthenticated attackers to upload arbitrary files to affected websites due to missing security checks. This vu...
Mar 19, 2025CVE-2025-2494 allows unrestricted file upload in Softdial Contact Center via the '/softdial/phpconsole/upload.php' endpoint, which is protected only b...
Mar 18, 2025This vulnerability allows attackers to upload malicious SVG or XML files to PublicCMS v4.0.202406, potentially leading to remote code execution. Attac...
Mar 6, 2025FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint that allows attackers to upload malicious...
Mar 4, 2025ShopXO 6.4.0 contains an unrestricted file upload vulnerability in ThemeDataService.php that allows attackers to upload malicious files. This can lead...
Feb 27, 2025An arbitrary file upload vulnerability in Jizhicms v2.5.4 allows attackers to upload malicious Zip files containing PHP code, which can be executed on...
Feb 26, 2025This vulnerability in the Everest Forms WordPress plugin allows unauthenticated attackers to upload, read, and delete arbitrary files on affected serv...
Feb 25, 2025This vulnerability allows unauthenticated attackers to download/upload files and execute API commands on YI Car Dashcam devices. Attackers can disable...
Feb 24, 2025The CleanTalk Security & Malware plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files via ZI...
Feb 12, 2025ChestnutCMS versions up to 1.5.0 contain a file upload vulnerability in the Create template function that allows attackers to upload malicious files. ...
Feb 3, 2025The ThemeREX Addons WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerabilit...
Jan 28, 2025The WPBookit WordPress plugin allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation. This vulnerability ...
Jan 25, 2025The WPBot Pro WordPress Chatbot plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to missing file t...
Jan 22, 2025CVE-2024-48760 is a critical remote code execution vulnerability in GestioIP v3.5.7 that allows attackers to upload malicious files and overwrite legi...
Jan 14, 2025ClipBucket V5 has a file upload vulnerability in the Manage Playlist functionality that allows attackers to upload PHP script files disguised as playl...
Jan 7, 2025This CVE describes a file upload vulnerability in ChestnutCMS that allows attackers to upload arbitrary files by bypassing extension validation. Attac...
Jan 6, 2025This vulnerability allows unauthenticated attackers to upload arbitrary files to the WukongCRM system via the /adminUser/updateImg endpoint. Successfu...
Jan 3, 2025This vulnerability in Apache Struts allows attackers to manipulate file upload parameters to perform path traversal attacks, potentially leading to re...
Dec 11, 2024Kashipara E-learning Management System v1.0 contains a remote code execution vulnerability in the teacher_avatar.php file upload functionality. Attack...
Dec 9, 2024This vulnerability allows attackers to bypass security restrictions and upload arbitrary files to Joomla websites using the Convert Forms component. A...
Dec 4, 2024DreamMaker from Interinfo has an unauthenticated path traversal vulnerability that allows attackers to upload arbitrary files to any directory. This c...
Nov 29, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the WPGYM Gym Management System plugin due to m...
Nov 23, 2024This vulnerability allows attackers to upload malicious .conf files to OmegaT's Roaming\Omega directory, leading to arbitrary code execution. It affec...
Nov 21, 2024HkCms versions up to v2.3.2.240702 contain an unrestricted file upload vulnerability in the Upload.php component. Attackers can upload malicious files...
Nov 20, 2024The Backup and Staging by WP Time Capsule WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validat...
Nov 16, 2024The WooCommerce Upload Files plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to upload arbitrary files to the ...
Nov 13, 2024This critical vulnerability in Webopac from Grand Vice info allows unauthenticated remote attackers to upload malicious files and execute arbitrary co...
Nov 11, 2024About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free