CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can exec
The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image file
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficie
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m
File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a c
Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such
An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by
An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrar
The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio
The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the '
The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insuf
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated
File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via u
A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload po
Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbi
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category imag
Unrestricted Upload of File with Dangerous Type vulnerability in OnTheGoSystems Types.This issue affects Types: from n/a
Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Edit
The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in
Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affect
The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attacker
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitr
ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, le
Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerabi
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, pri
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File w
The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrati
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attac
The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic
The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploadi
The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with
The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploa
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only avai
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via
File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the s
File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to exe
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via S
If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted val
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started