CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90
A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd
A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Af
A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown func
A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown pr
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before
A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /a
A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitra
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrat
An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads
The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arb
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uplo
Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Control
The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary comma
An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated a
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va
The CSV Me plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing
The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attac
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module direc
Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upl
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated atta
The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validatio
The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via
The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation
Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote atta
An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Contr
The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass
The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing f
The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr
The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss
EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to u
An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started