Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 29/87
4.7
CVE-2025-3123

A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the func

4.7
CVE-2025-3565

A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affect

4.7
CVE-2025-3798

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the

4.7
CVE-2025-4006

A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the

4.7
CVE-2025-4310

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unk

4.7
CVE-2025-4926

A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is som

4.7
CVE-2025-5059

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown p

4.7
CVE-2025-5130

A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function up

4.7
CVE-2025-5131

A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the

4.7
CVE-2025-6870

A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this

4.7
CVE-2025-6872

A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affect

4.7
CVE-2025-6873

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This iss

4.7
CVE-2025-7477

A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This is

4.7
CVE-2025-7898

A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part

4.7
CVE-2025-8265

A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admi

4.7
CVE-2025-8379

A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an

4.7
CVE-2025-9296

A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admi

4.7
CVE-2025-10081

A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/p

4.7
CVE-2025-11103

A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability

4.7
CVE-2025-11136

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/co

4.7
CVE-2025-11470

A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted e

4.7
CVE-2025-11508

A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the f

4.7
CVE-2025-11655

A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted elemen

4.7
CVE-2025-12201

A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1.

4.7
CVE-2025-12291

A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an u

4.7
CVE-2025-12331

A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add.

4.7
CVE-2025-12593

A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an u

4.7
CVE-2025-13185

A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the fi

4.7
CVE-2025-13198

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload

4.7
CVE-2025-13275

A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043

4.7
CVE-2025-13411

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unk

4.7
CVE-2025-13423

A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function

4.7
CVE-2025-13574

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd o

4.7
CVE-2025-14219

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown

4.7
CVE-2025-14530

A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknow

4.7
CVE-2025-14582

A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the

4.7
CVE-2025-14641

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the

4.7
CVE-2025-14642

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the f

4.7
CVE-2025-15110

A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Up

4.7
CVE-2025-15197

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vul

4.7
CVE-2025-15262

A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admi

4.7
CVE-2025-15360

A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd

4.6
CVE-2024-40513

An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload

4.6
CVE-2022-44760

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

4.6
CVE-2022-27562

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript

4.6
CVE-2022-42449

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript

4.3
CVE-2024-55417

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user u

4.3
CVE-2025-3325

A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part

4.3
CVE-2025-25016

Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a craf

4.3
CVE-2025-47866

An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an att

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started