CWE-434: Unrestricted File Upload

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

1,404
Total CVEs
697
Critical
592
High
8.8
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
92
2025
372
2024
385
2023
218
2022
145

Top Affected Vendors

1 Ibm 19
2 Zohocorp 12
3 Ivanti 12
4 Phpgurukul 7
5 Netgear 7
6 Oretnom23 7
7 Mingsoft 7
8 Dedecms 7
9 Apache 7
10 Debian 6

All Unrestricted File Upload CVEs (1,404)

CVE-2023-41506
9.8

This vulnerability allows attackers to upload arbitrary PHP files through the student profile picture upload function in Student Enrollment In PHP v1....

Feb 27, 2024
CVE-2024-25802
9.8

SKINsoft S-Museum 7.02.3 has an unrestricted file upload vulnerability in the Add Media function that allows attackers to upload malicious files. Unli...

Feb 22, 2024
CVE-2024-25274
9.8

This vulnerability allows attackers to upload arbitrary files to Novel-Plus systems via the /sysFile/upload endpoint, potentially leading to remote co...

Feb 20, 2024
CVE-2024-22824
9.8

CVE-2024-22824 is a critical unrestricted file upload vulnerability in Timo v.2.0.3 that allows remote attackers to bypass filetype restrictions and u...

Feb 20, 2024
CVE-2024-25414
9.8

CVE-2024-25414 is a critical arbitrary file upload vulnerability in CSZ CMS v1.3.0 that allows attackers to upload malicious Zip files containing PHP ...

Feb 16, 2024
CVE-2024-23759
9.8

CVE-2024-23759 is a critical deserialization vulnerability in Gambio e-commerce software that allows attackers to execute arbitrary code by exploiting...

Feb 12, 2024
CVE-2024-25674
9.8

This vulnerability in MISP allows attackers to upload malicious files disguised as organization logos due to insufficient file extension and MIME type...

Feb 9, 2024
CVE-2024-24393
9.8

This CVE describes a critical file upload vulnerability in Pichome v1.1.01 that allows remote attackers to upload malicious files and execute arbitrar...

Feb 8, 2024
CVE-2024-24202
9.8

This vulnerability allows authenticated attackers to upload malicious .txt files to the /upgrade/control.php endpoint in ZenTao products, leading to a...

Feb 8, 2024
CVE-2024-24025
9.8

An arbitrary file upload vulnerability in Novel-Plus v4.3.0-RC1 and earlier allows attackers to upload malicious files by manipulating the filename pa...

Feb 8, 2024
CVE-2024-24000
9.8

jshERP v3.3 has an arbitrary file upload vulnerability in the systemConfig/upload interface that allows attackers to upload malicious files to control...

Feb 6, 2024
CVE-2021-4436
9.8

CVE-2021-4436 is an unauthenticated arbitrary file upload vulnerability in the 3DPrint Lite WordPress plugin. Attackers can upload malicious files to ...

Feb 5, 2024
CVE-2023-6675
9.8

This vulnerability allows attackers to upload malicious files (like web shells) to CyberMath web servers due to insufficient file type validation. It ...

Feb 2, 2024
CVE-2023-51925
9.8

This vulnerability allows attackers to upload arbitrary files to YonBIP systems through a specific API endpoint, potentially leading to remote code ex...

Jan 20, 2024
CVE-2021-31314
9.8

This vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary server locations due to insufficie...

Jan 20, 2024
CVE-2023-27168
9.8

This vulnerability allows attackers to upload arbitrary JSP files to Xpand IT Write-back Manager v2.3.1, leading to remote code execution. Attackers c...

Jan 19, 2024
CVE-2023-6979
9.8

The Customer Reviews for WooCommerce WordPress plugin has a critical vulnerability that allows authenticated attackers with author-level access or hig...

Jan 11, 2024
CVE-2023-6316
9.8

The MW WP Form WordPress plugin allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation. This vulnerabilit...

Jan 11, 2024
CVE-2020-26629
9.8

CVE-2020-26629 is an unauthenticated arbitrary file upload vulnerability in Hospital Management System V4.0 that allows attackers to upload malicious ...

Jan 10, 2024
CVE-2023-50104
9.8

ZZCMS 2023 has an unauthenticated file upload vulnerability that allows attackers to upload malicious files and execute arbitrary code on the server. ...

Dec 29, 2023
CVE-2023-51034
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on TOTOlink EX1200L routers by exploiting the UploadFirmwareFile int...

Dec 22, 2023
CVE-2023-46263
9.8

This vulnerability allows attackers to upload malicious files to Avalanche systems, leading to remote code execution. It affects Avalanche versions 6....

Dec 19, 2023
CVE-2023-48376
9.8

SmartStar Software CWS has an unrestricted file upload vulnerability that allows unauthenticated attackers to upload malicious files. This can lead to...

Dec 15, 2023
CVE-2023-48371
9.8

CVE-2023-48371 is an unauthenticated remote code execution vulnerability in ITPison OMICARD EDM's file upload function. Attackers can upload malicious...

Dec 15, 2023
CVE-2023-48930
9.8

CVE-2023-48930 is an unrestricted file upload vulnerability in Xinhu OA 2.2.1 that allows attackers to upload malicious files to the server. This affe...

Dec 6, 2023
CVE-2023-5636
9.8

This vulnerability allows attackers to upload malicious files to ArslanSoft Education Portal, which can lead to command injection and remote code exec...

Dec 1, 2023
CVE-2023-41998
9.8

Arcserve UDP versions before 9.2 contain an unauthenticated remote code execution vulnerability in the RPSService4CPMImpl interface. Attackers can upl...

Nov 27, 2023
CVE-2023-5601
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress servers running the vulnerable WooCommerce Ninja Forms Prod...

Nov 6, 2023
CVE-2023-5360
9.8

This vulnerability in the Royal Elementor Addons and Templates WordPress plugin allows unauthenticated attackers to upload arbitrary files, including ...

Oct 31, 2023
CVE-2023-45554
9.8

This vulnerability in zzzCMS v2.1.9 allows remote attackers to bypass file upload restrictions by modifying the imageext parameter to include PHP exte...

Oct 25, 2023
CVE-2020-36706
9.8

This vulnerability in the Simple:Press WordPress plugin allows attackers to upload arbitrary files to affected WordPress sites due to missing file typ...

Oct 20, 2023
CVE-2023-45856
9.8

CVE-2023-45856 is a critical remote code execution vulnerability in qdPM 9.2 that allows attackers to upload malicious PHP files through the Add Attac...

Oct 14, 2023
CVE-2023-43269
9.8

CVE-2023-43269 is an arbitrary file upload vulnerability in pigcms that allows attackers to upload malicious files to the server. This affects all pig...

Oct 5, 2023
CVE-2023-44973
9.8

This vulnerability allows attackers to upload arbitrary PHP files to Emlog Pro's template directory, leading to remote code execution. It affects Emlo...

Oct 3, 2023
CVE-2023-44008
9.8

A file upload vulnerability in mojoPortal v2.7.0.0 allows remote attackers to upload malicious files through the File Manager function, potentially le...

Oct 2, 2023
CVE-2023-5227
9.8

This vulnerability allows attackers to upload malicious files to phpMyFAQ servers due to insufficient file type validation. Affects all phpMyFAQ insta...

Sep 30, 2023
CVE-2023-40784
9.8

DedeCMS 5.7.102 contains an unrestricted file upload vulnerability in the module_make.php component that allows attackers to upload arbitrary files, i...

Sep 12, 2023
CVE-2023-40980
9.8

This vulnerability allows remote attackers to upload malicious files to DWSurvey-OSS survey software, leading to arbitrary code execution on the serve...

Sep 1, 2023
CVE-2020-18912
9.8

CVE-2020-18912 is a critical remote code execution vulnerability in Earcms Ear App v.20181124 that allows attackers to execute arbitrary code via the ...

Aug 29, 2023
CVE-2023-32757
9.8

This vulnerability allows unauthenticated remote attackers to upload dangerous file types to e-Excellence U-Office Force systems. Attackers can execut...

Aug 25, 2023
CVE-2023-39970
9.8

CVE-2023-39970 is an unrestricted file upload vulnerability in the AcyMailing component for Joomla that allows attackers to upload malicious files. Th...

Aug 17, 2023
CVE-2023-38915
9.8

CVE-2023-38915 is a critical file upload vulnerability in Wolf-leo EasyAdmin8 v1.0 that allows remote attackers to upload malicious files and execute ...

Aug 15, 2023
CVE-2020-36082
9.8

CVE-2020-36082 is a critical file upload vulnerability in bloofoxCMS that allows remote attackers to upload malicious webshell files. This enables arb...

Aug 11, 2023
CVE-2023-32562
9.8

This vulnerability allows attackers to upload malicious files to Avalanche systems, leading to remote code execution. It affects all Avalanche version...

Aug 10, 2023
CVE-2023-32564
9.8

This vulnerability allows attackers to upload malicious files to Avalanche systems, leading to remote code execution. It affects Ivanti Avalanche vers...

Aug 10, 2023
CVE-2023-39776
9.8

This CVE describes a critical file upload vulnerability in PHPJabbers Ticket Support Script v3.2 that allows attackers to upload malicious files and e...

Aug 10, 2023
CVE-2023-32225
9.8

This vulnerability in Sysaid allows administrators to upload dangerous file types through an unspecified method. Attackers with administrative access ...

Jul 30, 2023
CVE-2023-34798
9.8

This vulnerability allows attackers to upload malicious files to eOffice systems, potentially leading to remote code execution. It affects eOffice ver...

Jul 25, 2023
CVE-2023-37677
9.8

CVE-2023-37677 is a remote code execution vulnerability in Pligg CMS (Kliqqi) v2.0.2 that allows attackers to execute arbitrary code on affected syste...

Jul 25, 2023
CVE-2023-32637
9.8

CVE-2023-32637 is a critical vulnerability in GBrowse that allows unauthenticated remote code execution. Attackers can upload malicious files through ...

Jul 25, 2023

About Unrestricted File Upload (CWE-434)

The product allows the upload of files with dangerous types that can be automatically processed within the product environment.

Our database tracks 1,404 CVEs classified as CWE-434, with 697 rated critical and 592 rated high severity. The average CVSS score for Unrestricted File Upload vulnerabilities is 8.8.

External reference: View CWE-434 on MITRE CWE →

Monitor Unrestricted File Upload Vulnerabilities

Get alerted when new Unrestricted File Upload CVEs affect your infrastructure.

Start Monitoring Free