CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when
One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could h
A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner
The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file up
The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid
Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor custom-icons-
Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit wdesignkit allows Upload a Web Shel
flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.
A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute
File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform versio
PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on
PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extensio
Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote att
IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files
An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file,
The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload func
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store
The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg fil
The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload f
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54,
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by t
A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This i
A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affect
A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affecte
A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects s
A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functio
A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This
A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is
A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnit
A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some
A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIn
A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function
A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the
A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function ac
A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability
A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unk
A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affec
A vulnerability classified as critical has been found in SourceCodester Online Mobile Management Store 1.0. This affects
A vulnerability was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. It has been declared as critic
A vulnerability classified as critical has been found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. Af
A vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. Affected by this issue is the functio
A vulnerability was found in PandaXGO PandaX up to 20240310. It has been classified as critical. Affected is an unknown
A vulnerability was found in SourceCodester File Manager App 1.0. It has been declared as critical. This vulnerability a
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started