CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerabi
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file
File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escal
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/wri
Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to inc
The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the si
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.
The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.
A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileU
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any u
When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be p
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and cod
An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary co
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not exec
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers t
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allow
Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to ex
go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download.
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute a
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vu
AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecifie
An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges v
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted
An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any typ
Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An a
The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and inclu
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pw
The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fet
The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aj
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary co
alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an exe
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnera
File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parame
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the functi
In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started