CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 24 of 92
- CVE-2021-45040CRITICALCVSS 9.8EG 9.82022-03-17
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
- CVE-2022-25495CRITICALCVSS 9.8EG 9.82022-03-15
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
- CVE-2022-25487CRITICALCVSS 9.8EG 9.82022-03-15
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
- CVE-2021-25003CRITICALCVSS 9.8EG 9.82022-03-14
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
- CVE-2022-24652CRITICALCVSS 9.8EG 9.82022-03-10
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.
- CVE-2022-24651CRITICALCVSS 9.8EG 9.82022-03-10
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.
- CVE-2022-25016CRITICALCVSS 9.8EG 9.82022-03-02
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP…
- CVE-2022-25411CRITICALCVSS 9.8EG 9.82022-02-28
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-24553CRITICALCVSS 9.8EG 9.82022-02-21
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.
- CVE-2021-46036CRITICALCVSS 9.8EG 9.82022-02-18
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
- CVE-2022-24984CRITICALCVSS 9.8EG 9.82022-02-16
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur…
- CVE-2022-23390CRITICALCVSS 9.8EG 9.82022-02-14
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
- CVE-2021-22803CRITICALCVSS 9.8EG 9.82022-02-11
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending…
- CVE-2020-13675CRITICALCVSS 9.8EG 9.82022-02-11
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass th…
- CVE-2022-23329CRITICALCVSS 9.8EG 9.82022-02-04
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
- CVE-2021-46428CRITICALCVSS 9.8EG 9.82022-01-27
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
- CVE-2021-46386CRITICALCVSS 9.8EG 9.82022-01-26
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
- CVE-2021-46033CRITICALCVSS 9.8EG 9.82022-01-25
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
- CVE-2022-23315CRITICALCVSS 9.8EG 9.82022-01-21
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
- CVE-2022-22929CRITICALCVSS 9.8EG 9.82022-01-21
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
- CVE-2021-46013CRITICALCVSS 9.8EG 9.82022-01-18
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing …
- CVE-2021-38697CRITICALCVSS 9.8EG 9.82022-01-18
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
- CVE-2021-45411CRITICALCVSS 9.8EG 9.82022-01-12
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
- CVE-2021-44031CRITICALCVSS 9.8EG 9.82021-12-22
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker coul…
- CVE-2021-44164CRITICALCVSS 9.8EG 9.82021-12-20
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pass file type validation, upload malicious script and execute arbitrary code without auth…
- CVE-2021-44159CRITICALCVSS 9.8EG 9.82021-12-20
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system op…
- CVE-2021-41560CRITICALCVSS 9.8EG 9.82021-12-15
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
- CVE-2021-40883CRITICALCVSS 9.8EG 9.82021-12-14
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
- CVE-2021-43117CRITICALCVSS 9.8EG 9.82021-12-13
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
- CVE-2021-42099CRITICALCVSS 9.8EG 9.82021-11-30
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
- CVE-2021-44093CRITICALCVSS 9.8EG 9.82021-11-28
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
- CVE-2021-43617CRITICALCVSS 9.8EG 9.82021-11-14
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on…
- CVE-2021-41833CRITICALCVSS 9.8EG 9.82021-11-11
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
- CVE-2021-28023CRITICALCVSS 9.8EG 9.82021-11-08
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by uploading a zip that extracts files in relative paths.
- CVE-2021-42669CRITICALCVSS 9.8EG 9.82021-11-05
A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/u…
- CVE-2020-18261CRITICALCVSS 9.8EG 9.82021-11-03
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
- CVE-2021-26740CRITICALCVSS 9.8EG 9.82021-11-01
Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.
- CVE-2021-41646CRITICALCVSS 9.8EG 9.82021-10-29
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
- CVE-2021-41644CRITICALCVSS 9.8EG 9.82021-10-29
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
- CVE-2021-41643CRITICALCVSS 9.8EG 9.82021-10-29
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
- CVE-2021-36548CRITICALCVSS 9.8EG 9.82021-10-28
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.
- CVE-2021-36547CRITICALCVSS 9.8EG 9.82021-10-28
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.
- CVE-2021-41745CRITICALCVSS 9.8EG 9.82021-10-22
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
- CVE-2021-42342CRITICALCVSS 9.8EG 9.82021-10-14
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables int…
- CVE-2021-20125CRITICALCVSS 9.8EG 9.82021-10-13
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files t…
- CVE-2021-41566CRITICALCVSS 9.8EG 9.82021-10-08
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.
- CVE-2021-37931CRITICALCVSS 9.8EG 9.82021-10-07
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- CVE-2021-37930CRITICALCVSS 9.8EG 9.82021-10-07
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- CVE-2021-37929CRITICALCVSS 9.8EG 9.82021-10-07
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- CVE-2021-37928CRITICALCVSS 9.8EG 9.82021-10-07
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →