CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote m
A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a
A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote ma
A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote m
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious use
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getLi
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbit
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Ad
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerabil
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege use
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege u
In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnera
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary fi
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to
The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating t
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high
GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can
An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulne
An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers
FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high
itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_tea
The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privil
Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upl
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_impo
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability
Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module edi
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Brandin
Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upl
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering Sys
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 a
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_E
Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "galle
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary file
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" f
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" fi
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php
DedeCMS 5.7.98 has a file upload vulnerability in the background.
An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management Sys
Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Executi
An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Managemen
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started