CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update o
A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the functi
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of
A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability
A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability aff
A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This
A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some u
A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue aff
A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unkn
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the fi
A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this
A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0.
A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects
A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects a
A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerab
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1
A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affecte
A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected b
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnera
A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected b
A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an
An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute
A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0.
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue af
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function Uploa
An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to exe
SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload i
gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigur
A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of t
NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an
File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could all
A vulnerability was found in ZhongFuCheng3y Austin 1.0 and classified as critical. This issue affects the function getFi
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality
An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arb
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which all
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basi
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of fil
IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted fi
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. P
As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulner
File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started