CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to exec
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil
An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary
An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code v
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.
An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NA
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execut
Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PH
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can e
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settin
The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload fil
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the ro
An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker
The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe
The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio
File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a
Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnera
The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to mis
An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arb
The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file uplo
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a c
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management Sys
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function
An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allow
GDidees CMS <= v3.9.1 has a file upload vulnerability.
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image uplo
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation
The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/li
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer
An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary
File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via
The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including,
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uplo
The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started