CWE-434: Unrestricted File Upload
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Yearly Trend
Top Affected Vendors
All Unrestricted File Upload CVEs (1,404)
The WooCommerce Support Ticket System plugin for WordPress has an unauthenticated arbitrary file upload vulnerability that allows attackers to upload ...
Nov 9, 2024This vulnerability allows attackers to upload and download files without restrictions in Cleo's Harmony, VLTrader, and LexiCom products, potentially l...
Oct 28, 2024The Wux Blog Editor WordPress plugin allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation. This vulnera...
Oct 26, 2024ClassCMS versions up to 4.8 contain a file inclusion vulnerability in the nowView method that allows attackers to include uploaded PHP files and execu...
Oct 16, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using vulnerable versions of the Frontend File Manage...
Oct 16, 2024The ZoomSounds WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation in the savepng.php file...
Oct 16, 2024This vulnerability allows unauthenticated attackers to create arbitrary PHP files on WordPress sites using the vulnerable Mega Menu plugin. Attackers ...
Oct 16, 2024This vulnerability allows remote attackers to upload malicious files disguised as images to execute arbitrary code on DYCMS servers. It affects all us...
Oct 15, 2024CVE-2024-42640 is an unauthenticated remote code execution vulnerability in angular-base64-upload versions prior to 0.1.21. Attackers can upload arbit...
Oct 11, 2024The Jupiter X Core WordPress plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to improper file typ...
Sep 26, 2024CVE-2023-26686 is a critical file upload vulnerability in CS-Cart MultiVendor 4.16.1 that allows remote attackers to upload malicious files through th...
Sep 25, 2024GDidees CMS v3.9.1 and earlier contains an unrestricted file upload vulnerability that allows attackers to upload malicious files, including webshells...
Sep 20, 2024Qualitor up to version 8.24 is vulnerable to remote code execution via arbitrary file upload in the checkAcesso.php endpoint. Attackers can upload mal...
Sep 9, 2024An unrestricted file upload vulnerability in Kashipara Music Management System v1.0 allows attackers to upload malicious PHP files through the signup ...
Aug 21, 2024CVE-2024-38530 is an unauthenticated arbitrary file upload vulnerability in Open eClass's H5P module that allows attackers to upload malicious files t...
Aug 12, 2024The YayExtra WooCommerce plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to missing...
Aug 3, 2024The Keydatas WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability affec...
Jul 17, 2024Simple Library Management System v1.0 contains an arbitrary file upload vulnerability in ajax.php that allows attackers to upload malicious files. Thi...
Jul 16, 2024This CVE describes a critical file upload vulnerability in Sparkshop (Spark Mall B2C Mall) that allows remote attackers to upload malicious files and ...
Jul 16, 2024This vulnerability allows attackers to upload malicious .cfm files to FarCry Core framework servers, leading to remote code execution. It affects all ...
Jun 25, 2024This vulnerability allows unauthenticated users (guests) to upload PHP files through the JA Marketplace module for PrestaShop. Attackers can exploit t...
Jun 19, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Salon booking system plugin. It affects all...
Jun 19, 2024CVE-2024-34833 is an unauthenticated remote code execution vulnerability in Sourcecodester Payroll Management System v1.0. Attackers can upload malici...
Jun 17, 2024CVE-2024-3912 is an arbitrary firmware upload vulnerability affecting certain ASUS router models. Unauthenticated remote attackers can exploit this to...
Jun 14, 2024This vulnerability allows an attacker to upload a malicious file to the certbadge.php endpoint in openeclass, potentially leading to remote code execu...
Jun 13, 2024CVE-2024-1659 is an unauthenticated arbitrary file upload vulnerability in MegaBIP software that allows attackers to upload malicious files (including...
Jun 12, 2024This vulnerability allows attackers to upload arbitrary files to Jan v0.4.12 via the /v1/app/writeFileSync interface, potentially leading to remote co...
Jun 4, 2024This critical vulnerability allows unauthenticated attackers to execute arbitrary code on affected Zyxel NAS devices by uploading a crafted configurat...
Jun 4, 2024This critical vulnerability in DedeCMS allows attackers to upload arbitrary files to the server, leading to remote code execution. Attackers can compr...
May 28, 2024This vulnerability allows attackers to upload malicious .jsp files through the uploadAudio method in inxedu v2024.4, leading to arbitrary code executi...
May 23, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to DedeCMS backend servers via the media_add.php page. Attackers can ach...
May 23, 2024The Hash Form WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability affe...
May 23, 2024Roothub v2.5 contains an arbitrary file upload vulnerability in the upload() function via the customPath parameter. Attackers can upload crafted JSP f...
May 7, 2024This vulnerability allows attackers to upload arbitrary files to the Zhongcheng Kexin Ticketing Management Platform, potentially leading to remote cod...
May 3, 2024This vulnerability allows unauthenticated remote attackers to upload arbitrary files to Voltronic Power ViewPower Pro systems, leading to remote code ...
May 3, 2024The InstaWP Connect WordPress plugin has an unauthenticated arbitrary file upload vulnerability in its REST API endpoint. This allows attackers to upl...
May 2, 2024This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress servers running the vulnerable Product Addons & Fields for ...
Apr 26, 2024ThinkCMF 6.0.9 contains an unrestricted file upload vulnerability in UeditorController.php that allows attackers to upload arbitrary files, including ...
Apr 25, 2024This CVE describes a critical file upload vulnerability in DedeCMS v5.7 that allows local attackers to upload malicious files and execute arbitrary co...
Apr 22, 2024jizhiCMS 2.5 contains an unrestricted file upload vulnerability that allows attackers to upload malicious files to the server. This affects all instal...
Apr 17, 2024This vulnerability allows attackers to download malicious .xrm-ms files without the usual executable file warning in Firefox, Thunderbird, and Firefox...
Apr 16, 2024This vulnerability in qdrant/qdrant allows attackers to upload arbitrary files to any location on the filesystem via a path traversal attack in the sn...
Apr 10, 2024This vulnerability in SEMCMS v4.8 allows remote attackers to upload malicious files via upload.php, leading to arbitrary code execution, privilege esc...
Apr 3, 2024This vulnerability in Mblog Blog system v3.5.0 allows remote attackers to execute arbitrary code by uploading a specially crafted file through the the...
Mar 28, 2024CVE-2024-28441 is a critical file upload vulnerability in magicflue versions 7.0 and earlier that allows remote attackers to upload malicious files an...
Mar 22, 2024This vulnerability allows attackers to include arbitrary PHP files in eyoucms v1.6.4 through template configuration manipulation, leading to remote co...
Mar 14, 2024Airflow-Diagrams v2.1.0 contains an arbitrary file upload vulnerability in the unsafe_load function that allows attackers to upload malicious YML file...
Mar 14, 2024This vulnerability allows attackers to upload malicious PHP files through the student profile picture upload function in Student Enrollment In PHP v1....
Mar 13, 2024This vulnerability allows authenticated users in CMS Made Simple to upload malicious files that bypass security filters, potentially leading to remote...
Mar 12, 2024CVE-2024-0864 is a remote code execution vulnerability in Laragon's Simple Ajax Uploader plugin due to improper input validation in file_upload.php. A...
Feb 29, 2024About Unrestricted File Upload (CWE-434)
The product allows the upload of files with dangerous types that can be automatically processed within the product environment.
Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.
External reference: View CWE-434 on MITRE CWE →
Monitor Unrestricted File Upload Vulnerabilities
Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.
Start Monitoring Free