Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 2/87
9.9
CVE-2026-40749

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

9.9
CVE-2026-56027

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

9.9
CVE-2026-56058

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

9.9
CVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

9.9
CVE-2026-27419

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.

9.9
CVE-2026-57710

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Usi

9.9
CVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCOR

9.9
CVE-2026-32463

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

9.9
CVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

9.9
CVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

9.9
CVE-2026-74014

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

9.9
CVE-2026-74016

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

9.9
CVE-2026-74018

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

9.9
CVE-2026-32559

Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

9.8
CVE-2019-25296

The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ

9.8
CVE-2025-67325

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated

9.8
CVE-2025-66802

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive

9.8
CVE-2025-65783

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.

9.8
CVE-2022-50893

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functio

9.8
CVE-2022-50912

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload p

9.8
CVE-2021-47753

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arb

9.8
CVE-2021-47819

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP

9.8
CVE-2025-67079

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng

9.8
CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p

9.8
CVE-2026-1331

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote

9.8
CVE-2025-70457

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up

9.8
CVE-2025-13374

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in

9.8
CVE-2025-69565

code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.

9.8
CVE-2025-69559

code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.

9.8
CVE-2026-25200

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto

9.8
CVE-2025-66480

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists

9.8
CVE-2025-61506

An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of

9.8
CVE-2025-69981

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut

9.8
CVE-2020-37090

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messag

9.8
CVE-2026-1357

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitr

9.8
CVE-2025-14014

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H

9.8
CVE-2026-1358

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maxim

9.8
CVE-2026-1306

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension

9.8
CVE-2026-2550

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file

9.8
CVE-2026-1405

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th

9.8
CVE-2025-14532

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension

9.8
CVE-2026-2743

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected fea

9.8
CVE-2026-21628

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading t

9.8
CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

9.8
CVE-2026-30821

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a

9.8
CVE-2026-3891

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and

9.8
CVE-2017-20224

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenti

9.8
CVE-2026-29859

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra

9.8
CVE-2026-32985

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te

9.8
CVE-2026-4809

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the pac

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started