CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 19 of 92
- CVE-2023-2071CRITICALCVSS 9.8EG 9.82023-09-12
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the func…
- CVE-2023-41009CRITICALCVSS 9.8EG 9.82023-09-05
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
- CVE-2023-4739CRITICALCVSS 9.8EG 9.82023-09-03
A vulnerability, which was classified as critical, has been found in Byzoro Smart S85F Management Platform up to 20230820. Affected by this issue is some unknown functionality of the file /sysmanage/updateos.php. The manipulation of the ar…
- CVE-2023-40980CRITICALCVSS 9.8EG 9.82023-09-01
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.
- CVE-2023-41637CRITICALCVSS 9.8EG 9.82023-08-31
An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.
- CVE-2023-4596CRITICALCVSS 9.8EG 9.82023-08-30
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. Th…
- CVE-2020-18912CRITICALCVSS 9.8EG 9.82023-08-29
An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.
- CVE-2023-38029CRITICALCVSS 9.8EG 9.82023-08-28
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files t…
- CVE-2023-4559CRITICALCVSS 9.8EG 9.82023-08-27
A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&action=user&m=upload of the component POST Request Handler. The…
- CVE-2023-32757CRITICALCVSS 9.8EG 9.82023-08-25
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform a…
- CVE-2023-39970CRITICALCVSS 9.8EG 9.82023-08-17
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
- CVE-2023-39115CRITICALCVSS 9.8EG 9.82023-08-16
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
- CVE-2023-38915CRITICALCVSS 9.8EG 9.82023-08-15
File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.
- CVE-2020-36082CRITICALCVSS 9.8EG 9.82023-08-11
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
- CVE-2023-32564CRITICALCVSS 9.8EG 9.82023-08-10
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
- CVE-2023-32562CRITICALCVSS 9.8EG 9.82023-08-10
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.
- CVE-2023-39776CRITICALCVSS 9.8EG 9.82023-08-10
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2023-4186CRITICALCVSS 9.8EG 9.82023-08-06
A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php. The manipulation leads to unrestricted…
- CVE-2023-4121CRITICALCVSS 9.8EG 9.82023-08-03
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown function. The manipulation of the argument file_upload leads to unrestricted upload. It is possib…
- CVE-2023-33493CRITICALCVSS 9.8EG 9.82023-08-01
An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop through 2.3.0, allows remote attackers to upload dangerous files without restrictions.
- CVE-2023-32225CRITICALCVSS 9.8EG 9.82023-07-30
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
- CVE-2023-37677CRITICALCVSS 9.8EG 9.82023-07-25
Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.
- CVE-2023-34798CRITICALCVSS 9.8EG 9.82023-07-25
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2023-32637CRITICALCVSS 9.8EG 9.82023-07-25
GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.
- CVE-2023-37289CRITICALCVSS 9.8EG 9.82023-07-20
It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit thi…
- CVE-2023-37839CRITICALCVSS 9.8EG 9.82023-07-13
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2023-34136CRITICALCVSS 9.8EG 9.82023-07-13
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier…
- CVE-2023-37629CRITICALCVSS 9.8EG 9.82023-07-12
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
- CVE-2023-37656CRITICALCVSS 9.8EG 9.82023-07-11
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
- CVE-2023-37152CRITICALCVSS 9.8EG 9.82023-07-10
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
- CVE-2020-22153CRITICALCVSS 9.8EG 9.82023-07-03
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
- CVE-2020-22151CRITICALCVSS 9.8EG 9.82023-07-03
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
- CVE-2020-18432CRITICALCVSS 9.8EG 9.82023-06-30
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
- CVE-2023-34738CRITICALCVSS 9.8EG 9.82023-06-29
Chemex through 3.7.1 is vulnerable to arbitrary file upload.
- CVE-2022-44276CRITICALCVSS 9.8EG 9.82023-06-28
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
- CVE-2023-2068CRITICALCVSS 9.8EG 9.82023-06-27
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not includ…
- CVE-2023-33404CRITICALCVSS 9.8EG 9.82023-06-26
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
- CVE-2023-36097CRITICALCVSS 9.8EG 9.82023-06-22
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
- CVE-2020-21489CRITICALCVSS 9.8EG 9.82023-06-20
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
- CVE-2020-21474CRITICALCVSS 9.8EG 9.82023-06-20
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
- CVE-2020-21174CRITICALCVSS 9.8EG 9.82023-06-20
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
- CVE-2020-20735CRITICALCVSS 9.8EG 9.82023-06-20
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
- CVE-2020-20718CRITICALCVSS 9.8EG 9.82023-06-20
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
- CVE-2023-32753CRITICALCVSS 9.8EG 9.82023-06-16
OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system comman…
- CVE-2023-32752CRITICALCVSS 9.8EG 9.82023-06-16
L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable…
- CVE-2023-34747CRITICALCVSS 9.8EG 9.82023-06-14
File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.
- CVE-2023-34944CRITICALCVSS 9.8EG 9.82023-06-13
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
- CVE-2023-31541CRITICALCVSS 9.8EG 9.82023-06-13
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
- CVE-2020-36705CRITICALCVSS 9.8EG 9.82023-06-07
The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated …
- CVE-2019-25138CRITICALCVSS 9.8EG 9.82023-06-07
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticat…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →