CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,555 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 1 of 92
- CVE-2026-48939CRITICALCVSS 10.0EG 10.0⚠ KEV2026-06-20
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
- CVE-2025-52691CRITICALCVSS 10.0EG 10.0⚠ KEV2025-12-29
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
- CVE-2020-25213CRITICALCVSS 10.0EG 10.0⚠ KEV2020-09-09
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example,…
- CVE-2025-31324CRITICALCVSS 9.8EG 10.0⚠ KEV2025-04-24
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significa…
- CVE-2024-57968CRITICALCVSS 9.9EG 9.9⚠ KEV2025-02-03
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this.
- CVE-2021-38163CRITICALCVSS 9.9EG 9.9⚠ KEV2021-09-14
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable o…
- CVE-2026-56291CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-09
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads…
- CVE-2026-56290CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-29
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
- CVE-2026-48908CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-20
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- CVE-2024-50623CRITICALCVSS 9.8EG 9.8⚠ KEV2024-10-28
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
- CVE-2024-7399CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-12
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
- CVE-2022-41352CRITICALCVSS 9.8EG 9.8⚠ KEV2022-09-26
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to an…
- CVE-2022-29464CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-18
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such a…
- CVE-2022-26871CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-29
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
- CVE-2021-27860CRITICALCVSS 9.8EG 9.8⚠ KEV2021-12-08
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The Fat…
- CVE-2021-22005CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-23
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specia…
- CVE-2021-40870CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-13
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
- CVE-2020-8599CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-18
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not requi…
- CVE-2018-15961CRITICALCVSS 9.8EG 9.8⚠ KEV2018-09-25
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2017-11357CRITICALCVSS 9.8EG 9.8⚠ KEV2017-08-23
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVE-2016-3088CRITICALCVSS 9.8EG 9.8⚠ KEV2016-06-01
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
- CVE-2021-36741CRITICALCVSS 8.8EG 9.0⚠ KEV2021-07-29
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: …
- CVE-2021-26828CRITICALCVSS 8.8EG 9.0⚠ KEV2021-06-11
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
- CVE-2020-13671CRITICALCVSS 8.8EG 9.0⚠ KEV2020-11-20
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This …
- CVE-2018-4063CRITICALCVSS 8.8EG 9.0⚠ KEV2019-05-06
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routa…
- CVE-2017-12617CRITICALCVSS 8.1EG 9.0⚠ KEV2017-10-04
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible…
- CVE-2017-12615CRITICALCVSS 8.1EG 9.0⚠ KEV2017-09-19
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted reques…
- CVE-2025-2749CRITICALCVSS 7.2EG 9.0⚠ KEV2025-03-24
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content tha…
- CVE-2024-39717CRITICALCVSS 7.2EG 9.0⚠ KEV2024-08-22
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do no…
- CVE-2024-7694CRITICALCVSS 7.2EG 9.0⚠ KEV2024-08-12
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary sy…
- CVE-2022-27925CRITICALCVSS 7.2EG 9.0⚠ KEV2022-04-21
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, lea…
- CVE-2021-20022CRITICALCVSS 7.2EG 9.0⚠ KEV2021-04-09
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
- CVE-2020-8260CRITICALCVSS 7.2EG 9.0⚠ KEV2020-10-28
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
- CVE-2021-31207CRITICALCVSS 6.6EG 9.0⚠ KEV2021-05-11
Microsoft Exchange Server Security Feature Bypass Vulnerability
- CVE-2019-8394CRITICALCVSS 6.5EG 9.0⚠ KEV2019-02-17
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
- CVE-2026-94503CRITICALCVSS 10.0EG 10.02026-10-09
Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.
- CVE-2026-39770CRITICALCVSS 10.0EG 10.02026-10-06
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
- CVE-2026-32579CRITICALCVSS 10.0EG 10.02026-10-06
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
- CVE-2026-102427CRITICALCVSS 10.0EG 10.02026-09-30
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or AC…
- CVE-2026-4357CRITICALCVSS 10.0EG 10.02026-09-02
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
- CVE-2026-84147CRITICALCVSS 10.0EG 10.02026-09-01
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files t…
- CVE-2026-81780CRITICALCVSS 10.0EG 10.02026-08-31
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
- CVE-2026-82970CRITICALCVSS 10.0EG 10.02026-08-31
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n…
- CVE-2026-75949CRITICALCVSS 10.0EG 10.02026-08-19
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enfo…
- CVE-2026-74803CRITICALCVSS 10.0EG 10.02026-08-19
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
- CVE-2026-66665CRITICALCVSS 10.0EG 10.02026-08-06
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-61424CRITICALCVSS 10.0EG 10.02026-07-20
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
- CVE-2026-61900CRITICALCVSS 10.0EG 10.02026-07-20
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
- CVE-2026-57719CRITICALCVSS 10.0EG 10.02026-07-13
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
- CVE-2026-48283CRITICALCVSS 10.0EG 10.02026-06-30
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue d…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →