CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Spect
CWE-434 Unrestricted Upload of File with Dangerous Type
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload fea
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can uploa
Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.p
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible
An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior t
The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user w
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte
WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the fil
Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in
Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This sec
FNT Command 13.4.0 is vulnerable to Directory Traversal.
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cr
File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary cod
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut
The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable wh
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficien
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads d
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not hav
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje
The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript p
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of
The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the C
IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in th
IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the fil
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangero
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Se
Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web S
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can us
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started