CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoi
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco
A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an un
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the
A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing
A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unkno
A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the func
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file s
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.p
A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the
A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown fu
A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the
A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4
A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the fu
A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of t
A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller
A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown f
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-cod
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is th
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert
A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-serve
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some un
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the fil
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Th
A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson
A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This is
A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects
A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=cust
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown functi
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This
A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat
docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the
A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file
FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricte
A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the f
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started