CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,555 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 15 of 92
- CVE-2025-29287CRITICALCVSS 9.8EG 9.82025-04-21
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2021-4455CRITICALCVSS 9.8EG 9.82025-04-19
The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to…
- CVE-2025-1093CRITICALCVSS 9.8EG 9.82025-04-19
The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to u…
- CVE-2024-40071CRITICALCVSS 9.8EG 9.82025-04-16
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via…
- CVE-2025-2005CRITICALCVSS 9.8EG 9.82025-04-02
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible fo…
- CVE-2024-56975CRITICALCVSS 9.8EG 9.82025-03-28
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.
- CVE-2025-29411CRITICALCVSS 9.8EG 9.82025-03-20
An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2024-8958CRITICALCVSS 9.8EG 9.82025-03-20
In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially l…
- CVE-2024-10901CRITICALCVSS 9.8EG 9.82025-03-20
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enab…
- CVE-2025-2512CRITICALCVSS 9.8EG 9.82025-03-19
The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the upload() function in all versions up to, and including, 3.9.9.0.1. This makes it possible …
- CVE-2024-57169CRITICALCVSS 9.8EG 9.82025-03-18
A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malic…
- CVE-2025-2494CRITICALCVSS 9.8EG 9.82025-03-18
Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authenticat…
- CVE-2025-25361CRITICALCVSS 9.8EG 9.82025-03-06
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.
- CVE-2025-26319CRITICALCVSS 9.8EG 9.82025-03-04
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
- CVE-2024-8425CRITICALCVSS 9.8EG 9.82025-02-28
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_wgm_preview_mail' and 'mwb_wgm_woocommerce_add_cart_item_data' functions in all versions u…
- CVE-2025-26325CRITICALCVSS 9.8EG 9.82025-02-27
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
- CVE-2025-25790CRITICALCVSS 9.8EG 9.82025-02-26
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
- CVE-2025-25784CRITICALCVSS 9.8EG 9.82025-02-26
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.
- CVE-2025-25783CRITICALCVSS 9.8EG 9.82025-02-26
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.
- CVE-2025-1128CRITICALCVSS 9.8EG 9.82025-02-25
The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format'…
- CVE-2024-56897CRITICALCVSS 9.8EG 9.82025-02-24
Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling re…
- CVE-2024-13365CRITICALCVSS 9.8EG 9.82025-02-12
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in a…
- CVE-2024-13011CRITICALCVSS 9.8EG 9.82025-02-10
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up to, and including, 4.7. This makes it possible for unau…
- CVE-2024-57450CRITICALCVSS 9.8EG 9.82025-02-03
ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
- CVE-2024-13448CRITICALCVSS 9.8EG 9.82025-01-28
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for un…
- CVE-2025-0357CRITICALCVSS 9.8EG 9.82025-01-25
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possibl…
- CVE-2024-13091CRITICALCVSS 9.8EG 9.82025-01-22
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible …
- CVE-2024-48760CRITICALCVSS 9.8EG 9.82025-01-14
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command executi…
- CVE-2025-22137CRITICALCVSS 9.8EG 9.82025-01-08
Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, includ…
- CVE-2022-41573CRITICALCVSS 9.8EG 9.82025-01-07
An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessib…
- CVE-2025-21624CRITICALCVSS 9.8EG 9.82025-01-07
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. W…
- CVE-2024-56828CRITICALCVSS 9.8EG 9.82025-01-06
File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarB…
- CVE-2024-55078CRITICALCVSS 9.8EG 9.82025-01-03
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2024-9290CRITICALCVSS 9.8EG 9.82024-12-13
The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up…
- CVE-2024-53677CRITICALCVSS 9.8EG 9.82024-12-11
File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execut…
- CVE-2024-54918CRITICALCVSS 9.8EG 9.82024-12-09
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
- CVE-2024-40744CRITICALCVSS 9.8EG 9.82024-12-04
Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.
- CVE-2024-11979CRITICALCVSS 9.8EG 9.82024-11-29
DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by…
- CVE-2024-9942CRITICALCVSS 9.8EG 9.82024-11-23
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. T…
- CVE-2024-9659CRITICALCVSS 9.8EG 9.82024-11-23
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. Th…
- CVE-2024-51366CRITICALCVSS 9.8EG 9.82024-11-21
An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file.
- CVE-2024-52677CRITICALCVSS 9.8EG 9.82024-11-20
HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.
- CVE-2024-11315CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11314CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11313CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11312CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11311CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-8856CRITICALCVSS 9.8EG 9.82024-11-16
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and in…
- CVE-2024-10820CRITICALCVSS 9.8EG 9.82024-11-13
The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possible for unauthentic…
- CVE-2024-11018CRITICALCVSS 9.8EG 9.82024-11-11
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →