CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc
School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitr
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulner
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability
The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t
Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a
Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php a
CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerabi
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl
DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arb
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur
The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content impo
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path t
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded throug
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to ac
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a
CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability.
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arb
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fi
A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including
PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitr
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18
2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executab
i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensi
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started