CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the s
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, all
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious fil
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload fil
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupl
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalo
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the compon
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remo
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp f
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malic
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uplo
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload t
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execu
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to uploa
Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers
Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\d
eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows
An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a mal
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerabi
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. Th
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. Th
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t
Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?se
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerabi
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u
ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_use
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&p
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <=
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi
An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code
An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photo
In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.p
In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started