Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 4/87
9.8
CVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten

9.8
CVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS

9.8
CVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module.

9.8
CVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path)

9.8
CVE-2022-4995

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent

9.8
CVE-2026-19089

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its ac

9.8
CVE-2026-72592

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e

9.8
CVE-2026-15039

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all

9.8
CVE-2026-18391

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor

9.8
CVE-2026-49827

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow

9.8
CVE-2026-16098

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi

9.8
CVE-2026-67678

File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

9.8
CVE-2026-15748

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1

9.8
CVE-2026-73996

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

9.8
CVE-2026-16286

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware

9.8
CVE-2026-80235

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote atta

9.8
CVE-2026-18080

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi

9.8
CVE-2025-61165

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac

9.8
CVE-2026-14494

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.

9.6
CVE-2026-22783

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior

9.6
CVE-2025-69771

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14

9.6
CVE-2026-28192

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

9.3
CVE-2026-48356

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi

9.1
CVE-2023-50897

Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Fil

9.1
CVE-2025-67910

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload

9.1
CVE-2025-69312

Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows

9.1
CVE-2025-57794

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ

9.1
CVE-2026-25923

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to

9.1
CVE-2025-13590

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d

9.1
CVE-2026-23802

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious F

9.1
CVE-2026-28114

Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manag

9.1
CVE-2026-27067

Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa

9.1
CVE-2026-32524

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web S

9.1
CVE-2026-2701

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

9.1
CVE-2026-35174

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin

9.1
CVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's back

9.1
CVE-2026-40484

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional

9.1
CVE-2026-6257

Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing

9.1
CVE-2026-45053

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists

9.1
CVE-2026-9067

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend

9.1
CVE-2026-57658

Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.

9.1
CVE-2026-58409

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve

9.1
CVE-2026-27064

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

9.1
CVE-2026-65455

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

9.1
CVE-2026-65461

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

9.1
CVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti

9.1
CVE-2026-66600

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

9.1
CVE-2026-49849

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allo

9.1
CVE-2026-78274

Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

9.0
CVE-2026-24769

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS)

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started