CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.
The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i
The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the
The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the '
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML e
The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which c
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'for
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file ty
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specify
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and
An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not wri
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to c
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to c
An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined
An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are a
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attac
A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the c
A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerabi
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and c
A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected b
A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the fu
A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown
A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processin
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. Thi
A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an
A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0
A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. Th
A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component
A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functional
A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. Thi
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affect
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin
A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulne
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMe
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of th
A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerabilit
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior t
A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by t
Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC
A vulnerability was found in code-projects Agro-School Management System 1.0 and classified as critical. This issue affe
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started