CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary Fil
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPres
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing au
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to ex
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that all
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attack
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that al
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated use
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S
baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves upl
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the a
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFi
Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access
Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix fi
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell
River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows lo
FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to exec
RGui 3.5.0 contains a local buffer overflow vulnerability in the GUI preferences dialog that allows attackers to bypass
Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remo
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by
ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R
Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows Fi
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in
The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versi
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial
An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a c
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell t
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass v
Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process do
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploa
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/s
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all vers
A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/we
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started