CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut
The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in
An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-a
NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated pa
WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload mal
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup res
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attac
File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions al
WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editin
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploade
Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in u
PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execut
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files throug
MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized user
Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension rest
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9
The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation i
GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renamin
An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a
Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with a
The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in
A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote a
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge no
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated adm
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o
Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to u
Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon
IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to s
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestr
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Vers
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An atta
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, an
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner
Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co
The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and in
Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started