CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,404
Total CVEs
697
Critical
592
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,404)

CVE-2025-6222
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the WooCommerce Refund And Exchange plugin due ...

Jul 18, 2025
CVE-2025-7340
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the HT Contact Form Widget plugin due to missin...

Jul 15, 2025
CVE-2020-36849
EPSS 72.2% 9.8

The AIT CSV import/export WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulner...

Jul 12, 2025
CVE-2020-36847
EPSS 86.1% 9.8

This vulnerability allows unauthenticated attackers to rename uploaded PHP files with .png extensions to .php extensions, enabling remote code executi...

Jul 12, 2025
CVE-2025-6058
EPSS 22.8% 9.8

The WPBookit WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability can l...

Jul 12, 2025
CVE-2025-6802
9.8

This vulnerability allows unauthenticated remote attackers to upload arbitrary files to Marvell QConvergeConsole servers, leading to remote code execu...

Jul 7, 2025
CVE-2025-5746
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress servers running vulnerable versions of the Drag and Drop Mu...

Jul 2, 2025
CVE-2014-0468
9.8

This vulnerability in FusionForge's Apache configuration allows remote code execution by enabling attackers to execute arbitrary scripts uploaded to S...

Jun 26, 2025
CVE-2025-48782
9.8

This vulnerability allows remote attackers to upload malicious files to the Soar Cloud HRD Human Resource Management System, which can lead to arbitra...

Jun 6, 2025
CVE-2025-48471
9.8

FreeScout versions before 1.8.179 have an unrestricted file upload vulnerability that allows attackers to upload malicious PHP files (.phtml, .phar ex...

May 29, 2025
CVE-2025-4389
9.8

The Crawlomatic WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability af...

May 17, 2025
CVE-2025-47787
9.8

Emlog Pro versions before 2.5.10 contain a critical file upload vulnerability in the store.php component that fails to properly validate remotely down...

May 15, 2025
CVE-2025-3917
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the η™ΎεΊ¦η«™ι•ΏSEOεˆι›† plugin. Attackers can...

May 15, 2025
CVE-2024-11617
9.8

The Envolve Plugin for WordPress allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability af...

May 9, 2025
CVE-2023-31585
9.8

Grocery-CMS-PHP-Restful-API v1.3 has an unrestricted file upload vulnerability in the /admin/add-category.php endpoint that allows attackers to upload...

May 8, 2025
CVE-2025-29287
9.8

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to upload malicious files that can lead to remote code...

Apr 21, 2025
CVE-2021-4455
9.8

The Smart Product Review WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnera...

Apr 19, 2025
CVE-2025-1093
9.8

The AIHub WordPress theme allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the generate_image functio...

Apr 19, 2025
CVE-2024-40071
9.8

This vulnerability allows attackers to upload arbitrary PHP files to Sourcecodester Online ID Generator System 1.0, leading to remote code execution. ...

Apr 16, 2025
CVE-2025-2005
9.8

The Front End Users WordPress plugin allows unauthenticated attackers to upload arbitrary files through registration forms due to missing file type va...

Apr 2, 2025
CVE-2025-29411
9.8

An arbitrary file upload vulnerability in Mart Developers iBanking v2.0.0 allows authenticated attackers to upload malicious PHP files through the Cli...

Mar 20, 2025
CVE-2024-8958
9.8

This vulnerability allows attackers to read and write arbitrary files on servers running composiohq/composio version 0.4.3 due to improper path valida...

Mar 20, 2025
CVE-2024-10901
9.8

This vulnerability in eosphoros-ai/db-gpt allows attackers to execute arbitrary SQL queries via an unprotected web API endpoint, leading to arbitrary ...

Mar 20, 2025
CVE-2025-2512
9.8

The File Away WordPress plugin allows unauthenticated attackers to upload arbitrary files to affected websites due to missing security checks. This vu...

Mar 19, 2025
CVE-2025-2494
9.8

CVE-2025-2494 allows unrestricted file upload in Softdial Contact Center via the '/softdial/phpconsole/upload.php' endpoint, which is protected only b...

Mar 18, 2025
CVE-2025-25361
9.8

This vulnerability allows attackers to upload malicious SVG or XML files to PublicCMS v4.0.202406, potentially leading to remote code execution. Attac...

Mar 6, 2025
CVE-2025-26319
EPSS 78.8% 9.8

FlowiseAI Flowise v2.2.6 contains an arbitrary file upload vulnerability in the /api/v1/attachments endpoint that allows attackers to upload malicious...

Mar 4, 2025
CVE-2025-26325
9.8

ShopXO 6.4.0 contains an unrestricted file upload vulnerability in ThemeDataService.php that allows attackers to upload malicious files. This can lead...

Feb 27, 2025
CVE-2025-25784
9.8

An arbitrary file upload vulnerability in Jizhicms v2.5.4 allows attackers to upload malicious Zip files containing PHP code, which can be executed on...

Feb 26, 2025
CVE-2025-1128
9.8

This vulnerability in the Everest Forms WordPress plugin allows unauthenticated attackers to upload, read, and delete arbitrary files on affected serv...

Feb 25, 2025
CVE-2024-56897
9.8

This vulnerability allows unauthenticated attackers to download/upload files and execute API commands on YI Car Dashcam devices. Attackers can disable...

Feb 24, 2025
CVE-2024-13365
9.8

The CleanTalk Security & Malware plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files via ZI...

Feb 12, 2025
CVE-2024-57450
9.8

ChestnutCMS versions up to 1.5.0 contain a file upload vulnerability in the Create template function that allows attackers to upload malicious files. ...

Feb 3, 2025
CVE-2024-13448
9.8

The ThemeREX Addons WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerabilit...

Jan 28, 2025
CVE-2025-0357
9.8

The WPBookit WordPress plugin allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation. This vulnerability ...

Jan 25, 2025
CVE-2024-13091
9.8

The WPBot Pro WordPress Chatbot plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to missing file t...

Jan 22, 2025
CVE-2024-48760
9.8

CVE-2024-48760 is a critical remote code execution vulnerability in GestioIP v3.5.7 that allows attackers to upload malicious files and overwrite legi...

Jan 14, 2025
CVE-2025-21624
EPSS 23% 9.8

ClipBucket V5 has a file upload vulnerability in the Manage Playlist functionality that allows attackers to upload PHP script files disguised as playl...

Jan 7, 2025
CVE-2024-56828
9.8

This CVE describes a file upload vulnerability in ChestnutCMS that allows attackers to upload arbitrary files by bypassing extension validation. Attac...

Jan 6, 2025
CVE-2024-55078
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to the WukongCRM system via the /adminUser/updateImg endpoint. Successfu...

Jan 3, 2025
CVE-2024-53677
9.8

This vulnerability in Apache Struts allows attackers to manipulate file upload parameters to perform path traversal attacks, potentially leading to re...

Dec 11, 2024
CVE-2024-54918
9.8

Kashipara E-learning Management System v1.0 contains a remote code execution vulnerability in the teacher_avatar.php file upload functionality. Attack...

Dec 9, 2024
CVE-2024-40744
9.8

This vulnerability allows attackers to bypass security restrictions and upload arbitrary files to Joomla websites using the Convert Forms component. A...

Dec 4, 2024
CVE-2024-11979
9.8

DreamMaker from Interinfo has an unauthenticated path traversal vulnerability that allows attackers to upload arbitrary files to any directory. This c...

Nov 29, 2024
CVE-2024-9942
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the WPGYM Gym Management System plugin due to m...

Nov 23, 2024
CVE-2024-51366
9.8

This vulnerability allows attackers to upload malicious .conf files to OmegaT's Roaming\Omega directory, leading to arbitrary code execution. It affec...

Nov 21, 2024
CVE-2024-52677
9.8

HkCms versions up to v2.3.2.240702 contain an unrestricted file upload vulnerability in the Upload.php component. Attackers can upload malicious files...

Nov 20, 2024
CVE-2024-8856
9.8

The Backup and Staging by WP Time Capsule WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validat...

Nov 16, 2024
CVE-2024-10820
9.8

The WooCommerce Upload Files plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to upload arbitrary files to the ...

Nov 13, 2024
CVE-2024-11018
9.8

This critical vulnerability in Webopac from Grand Vice info allows unauthenticated remote attackers to upload malicious files and execute arbitrary co...

Nov 11, 2024

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free