CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This v
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain ful
Windows Server Service Tampering Vulnerability
An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XS
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upl
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo func
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to exec
Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulner
The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upl
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 all
The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authe
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's loc
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. Th
Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any ext
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to ach
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a c
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbit
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to ren
Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.
Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Manageme
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with
In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks,
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requir
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary cod
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
SENS v1.0 has a file upload vulnerability.
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (ev
Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.
File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a De
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Re
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. W
sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is kn
Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges.
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started