CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module.
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path)
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its ac
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote atta
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior
Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi
Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Fil
Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload
Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows
Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious F
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manag
Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web S
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin
ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's back
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional
Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing
CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists
The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allo
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS)
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started