CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p
An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to the
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than t
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbi
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbi
The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing c
Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attacke
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upl
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute ar
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular priv
The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up
MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitr
MarkUs is a web application for the submission and grading of student assignments. In versions prior to 2.4.8, an arbitr
An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f
An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.
The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability
The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Managemen
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up
ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer f
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a th
Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted u
Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnera
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from
An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admi
Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote co
A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arb
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.T
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is
Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue aff
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form bit-form.This issue affects Bit Form:
Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started