CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webr
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can uplo
A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.ph
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Co
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Ba
Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/pl
IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous f
The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management ri
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficien
Microsoft Exchange Server Security Feature Bypass Vulnerability
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's avai
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Si
Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background witho
WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because th
An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote
An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extensio
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a store
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitra
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5,
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does n
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, wh
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An att
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, wh
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote cod
A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center
In Phproject before version 1.7.8, there's a vulnerability which allows users with access to file uploads to execute arb
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in
An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an aut
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started