CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbi
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor
The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fail
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero
The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att
Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that lo
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar
The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va
The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all
The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid
The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a
QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script"
The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc
The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to,
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem
The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi
The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida
The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th
The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,
The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insuf
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid
The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validatio
The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to
appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo
Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP
WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali
An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows att
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator
The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and
The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload m
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica
UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious
An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions t
File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious
Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar
Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P
Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitr
WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started