CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicio
Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Conten
A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil
A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown functi
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite
A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown funct
A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic
A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability
A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncl
A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown funct
A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.p
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTem
A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown fun
A flaw has been found in SourceCodester/jkev Record Management System 1.0. Affected by this issue is some unknown functi
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file applicat
A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/Ap
A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of t
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file
A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file
A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm
A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryControl
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings o
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function sa
A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints i
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the admi
The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted fi
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller o
Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers t
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accep
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t
The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upl
YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read l
IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be e
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content
Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability,
Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_up
Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-pl
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started