CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestric
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is
The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia
In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions,
The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ext
The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to mis
The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing
The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file uplo
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check
The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized
The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to up
The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missi
The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenti
The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitr
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through vers
The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achi
In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent bina
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the han
The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
CWE-434 Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sa
The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_g
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in
The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the re
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the i
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac
The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started