CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A vulnerability was found in Muyun DedeBIZ up to 6.2.12 and classified as critical. Affected by this issue is some unkno
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting fr
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with mod
A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this is
A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects
A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validati
A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2
Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to uploa
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker
LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system comm
In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may all
There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol
There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/repla
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files w
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attac
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileCon
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafte
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versi
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute ar
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to ex
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resul
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the c
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to w
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and e
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.j
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervi
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in
An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execu
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functio
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started