CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Usi
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCOR
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive
An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.
VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functio
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload p
phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arb
ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP
File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up
The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto
Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists
An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messag
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitr
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H
Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maxim
The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension
A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file
The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected fea
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading t
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenti
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te
plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the pac
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started