CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Lt
The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra
The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all
Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload mali
xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr
Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP file
Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrar
Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malic
The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publicatio
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to
A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmwa
File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become
File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue aff
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied file
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp
Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload
There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validat
Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify appointify allows Upload a Web Sh
Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell
Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator
Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high priv
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbi
An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-
An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The
Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility a
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated L
Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malici
File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q
On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip
daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs be
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner
/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such
In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userCont
The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missin
A vulnerability was found in Campcodes Project Management System 1.0. It has been declared as critical. This vulnerabili
A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the
A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function add
A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEd
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the functi
A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function
A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/up
A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this is
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started