Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 11/87
6.3
CVE-2026-10205

A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function o

6.3
CVE-2026-10806

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PH

6.3
CVE-2026-10807

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file applicati

6.3
CVE-2026-42538

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi

6.3
CVE-2026-11333

A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a

6.3
CVE-2026-48946

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma

6.3
CVE-2026-14698

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. I

6.3
CVE-2026-14775

A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unkn

6.3
CVE-2026-14776

A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by th

6.3
CVE-2026-14777

A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this is

6.3
CVE-2026-16451

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts

6.3
CVE-2026-18927

A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d4

6.3
CVE-2026-19065

A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects

6.3
CVE-2026-19210

A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of

6.3
CVE-2024-14046

A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController

6.3
CVE-2026-76800

A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dial

6.3
CVE-2026-77681

A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown function

6.2
CVE-2019-25616

AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application b

6.1
CVE-2025-14842

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files wi

6.1
CVE-2025-70849

Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST

6.1
CVE-2026-6835

The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to

6.1
CVE-2025-40808

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),

6.1
CVE-2026-19852

NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers

5.7
CVE-2025-55267

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio

5.6
CVE-2026-4830

A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/

5.5
CVE-2026-23636

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form

5.5
CVE-2025-36074

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to m

5.4
CVE-2026-22789

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 con

5.4
CVE-2021-47783

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files wi

5.4
CVE-2026-23499

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor

5.4
CVE-2026-24034

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scri

5.4
CVE-2026-22707

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con

5.4
CVE-2026-36722

An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows atta

5.4
CVE-2026-39527

Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

5.4
CVE-2026-53948

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied C

5.3
CVE-2025-12500

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limi

5.3
CVE-2026-1969

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing

5.3
CVE-2026-33809

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excess

5.3
CVE-2026-30280

An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 al

5.3
CVE-2025-14938

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and

5.3
CVE-2026-48945

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re

5.3
CVE-2026-15553

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote

5.3
CVE-2026-14906

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t

5.3
CVE-2026-11579

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload

5.3
CVE-2026-44103

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore

5.3
CVE-2026-71434

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms

5.3
CVE-2026-55419

Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/

5.3
CVE-2026-79706

The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to buil

5.0
CVE-2026-5704

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to

4.9
CVE-2026-28270

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started