Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 20/87
8.8
CVE-2025-56263

by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbi

8.8
CVE-2025-9216

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor

8.8
CVE-2025-10647

The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati

8.8
CVE-2025-56515

File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fail

8.8
CVE-2025-11020

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex

8.8
CVE-2025-11221

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero

8.8
CVE-2025-9561

The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic

8.8
CVE-2025-35055

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar

8.8
CVE-2025-61417

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att

8.8
CVE-2020-36863

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that lo

8.8
CVE-2025-11755

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar

8.8
CVE-2025-12171

The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va

8.8
CVE-2025-11724

The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all

8.8
CVE-2025-12161

The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid

8.8
CVE-2025-12846

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a

8.8
CVE-2025-63748

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script"

8.8
CVE-2025-12775

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc

8.8
CVE-2025-13069

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to,

8.8
CVE-2025-41735

A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem

8.8
CVE-2025-12138

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida

8.8
CVE-2025-13156

The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi

8.8
CVE-2025-13536

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida

8.8
CVE-2025-13543

The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in th

8.8
CVE-2025-13066

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,

8.8
CVE-2025-12153

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat

8.8
CVE-2025-12154

The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in

8.8
CVE-2025-12181

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th

8.8
CVE-2025-65897

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insuf

8.8
CVE-2025-12966

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid

8.8
CVE-2025-13065

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,

8.8
CVE-2025-56704

LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validatio

8.8
CVE-2025-14390

The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to

8.8
CVE-2024-58279

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to uplo

8.8
CVE-2024-58281

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP

8.8
CVE-2024-58283

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload mali

8.8
CVE-2025-65471

An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows att

8.8
CVE-2025-34506

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator

8.8
CVE-2025-12968

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and

8.8
CVE-2025-13094

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid

8.8
CVE-2024-44598

FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

8.8
CVE-2023-53868

Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload m

8.8
CVE-2025-66449

ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica

8.8
CVE-2023-53924

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo

8.8
CVE-2023-53933

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious

8.8
CVE-2019-25229

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions t

8.8
CVE-2023-53942

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious

8.8
CVE-2025-14849

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar

8.8
CVE-2023-53952

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P

8.8
CVE-2023-53956

Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitr

8.8
CVE-2023-53971

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started