CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,384 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 3 of 88
- CVE-2015-10135CRITICALCVSS 9.8EG 9.82025-07-19
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upl…
- CVE-2015-10137CRITICALCVSS 9.8EG 9.82025-07-22
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for …
- CVE-2015-10138CRITICALCVSS 9.8EG 9.82025-07-19
The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it pos…
- CVE-2015-10144HIGHCVSS 8.8EG 8.82025-07-25
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, w…
- CVE-2015-1784HIGHCVSS 8.8EG 8.82022-07-07
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lac…
- CVE-2015-1785MEDIUMCVSS 6.5EG 6.52022-07-07
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lac…
- CVE-2015-2780CRITICALCVSS 9.8EG 9.82017-10-16
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified dire…
- CVE-2015-3884CRITICALCVSS 8.8EG 9.82017-03-17
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pages in qdPM 8.3 allows remote attackers to execute arbitrary code by uploading a file with…
- CVE-2015-4455CRITICALCVSS 9.8EG 9.82017-05-23
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extens…
- CVE-2015-4462MEDIUMCVSS 6.5EG 6.52017-07-25
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for pro…
- CVE-2015-4463MEDIUMCVSS 6.5EG 6.52017-07-25
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.
- CVE-2015-4553HIGHCVSS 8.8EG 8.92020-01-06
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
- CVE-2015-5601HIGHCVSS 8.8EG 8.82019-07-29
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
- CVE-2015-5951CRITICALCVSS 9.9EG 9.92020-01-06
A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.
- CVE-2015-6000HIGHCVSS 8.8EG 8.82020-02-06
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary …
- CVE-2015-7339HIGHCVSS 8.8EG 8.82020-03-09
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
- CVE-2015-7341HIGHCVSS 8.8EG 8.82020-03-09
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
- CVE-2015-7571HIGHCVSS 7.8EG 7.82017-08-07
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
- CVE-2015-8249CRITICALCVSS 9.8EG 9.82017-09-28
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
- CVE-2015-9228HIGHCVSS 8.8EG 8.82017-09-12
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
- CVE-2015-9259CRITICALCVSS 9.8EG 9.82018-03-31
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker…
- CVE-2015-9263CRITICALCVSS 9.8EG 9.82018-08-27
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
- CVE-2015-9271CRITICALCVSS 9.8EG 9.82018-10-04
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrat…
- CVE-2015-9338HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
- CVE-2015-9339HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
- CVE-2015-9340HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
- CVE-2015-9341HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
- CVE-2015-9402HIGHCVSS 8.8EG 8.82019-09-20
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
- CVE-2015-9471CRITICALCVSS 9.8EG 9.82019-10-10
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
- CVE-2015-9479CRITICALCVSS 9.8EG 9.82019-10-10
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
- CVE-2015-9499CRITICALCVSS 9.8EG 9.82019-10-22
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
- CVE-2016-0354MEDIUMCVSS 5.5EG 5.52017-08-29
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM …
- CVE-2016-10036CRITICALCVSS 9.8EG 9.82018-05-01
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write t…
- CVE-2016-10258MEDIUMCVSS 6.8EG 6.82018-04-11
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another admi…
- CVE-2016-10751HIGHCVSS 7.2EG 7.22019-05-24
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?pa…
- CVE-2016-10752CRITICALCVSS 9.8EG 9.82019-05-24
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
- CVE-2016-10758HIGHCVSS 8.8EG 8.82019-05-24
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.
- CVE-2016-10954CRITICALCVSS 9.8EG 9.82019-09-13
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
- CVE-2016-10955CRITICALCVSS 9.8EG 9.82019-09-13
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
- CVE-2016-10958HIGHCVSS 7.5EG 7.52019-09-16
The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.
- CVE-2016-10959MEDIUMCVSS 6.5EG 6.52019-09-16
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.
- CVE-2016-10995CRITICALCVSS 9.8EG 9.82019-09-18
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
- CVE-2016-11020CRITICALCVSS 9.8EG 9.82020-02-25
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
- CVE-2016-15033CRITICALCVSS 9.8EG 9.82023-06-07
The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthen…
- CVE-2016-15042CRITICALCVSS 9.8EG 9.82024-10-16
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfr…
- CVE-2016-15043CRITICALCVSS 9.8EG 9.82025-07-19
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to uploa…
- CVE-2016-15046HIGHCVSS 8.6EG 8.62025-07-25
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port …
- CVE-2016-1713HIGHCVSS 7.3EG 7.32017-04-14
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uplo…
- CVE-2016-20052CRITICALCVSS 9.8EG 9.82026-04-04
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the m…
- CVE-2016-2914MEDIUMCVSS 5.4EG 5.42016-08-08
Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →