CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,555 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 5 of 92
- CVE-2023-51473CRITICALCVSS 9.8EG 10.02023-12-29
Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3.
- CVE-2023-51468CRITICALCVSS 9.8EG 10.02023-12-29
Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.
- CVE-2023-51419CRITICALCVSS 9.8EG 10.02023-12-29
Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BERTHA AI. Your AI co-pilot for WordPress and Chrome: from n/a through 1.11.10.7.
- CVE-2023-51411CRITICALCVSS 9.8EG 10.02023-12-29
Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3.
- CVE-2023-25970CRITICALCVSS 9.8EG 10.02023-12-20
Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.
- CVE-2023-6723CRITICALCVSS 9.8EG 10.02023-12-13
An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation controls, resulting in a…
- CVE-2023-3049CRITICALCVSS 9.8EG 10.02023-06-13
Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.
- CVE-2023-2712CRITICALCVSS 9.8EG 10.02023-05-20
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue …
- CVE-2023-1728CRITICALCVSS 9.8EG 10.02023-04-04
Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection. This issue affects LMS: before 23.04.03.
- CVE-2022-40981CRITICALCVSS 5.9EG 10.02022-11-10
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful exis…
- CVE-2026-62129CRITICALCVSS 9.9EG 9.92026-10-10
Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.
- CVE-2026-62024CRITICALCVSS 9.9EG 9.92026-10-10
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
- CVE-2026-39759CRITICALCVSS 9.9EG 9.92026-10-06
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
- CVE-2026-39757CRITICALCVSS 9.9EG 9.92026-10-06
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
- CVE-2026-39755CRITICALCVSS 9.9EG 9.92026-10-06
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
- CVE-2026-32559CRITICALCVSS 9.9EG 9.92026-08-24
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
- CVE-2026-74018CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
- CVE-2026-74016CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
- CVE-2026-74014CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
- CVE-2026-66627CRITICALCVSS 9.9EG 9.92026-08-18
Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.
- CVE-2026-32474CRITICALCVSS 9.9EG 9.92026-08-18
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
- CVE-2026-32463CRITICALCVSS 9.9EG 9.92026-08-18
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
- CVE-2026-63227CRITICALCVSS 9.9EG 9.92026-07-29
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.
- CVE-2026-57710CRITICALCVSS 9.9EG 9.92026-07-13
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
- CVE-2026-27419CRITICALCVSS 9.9EG 9.92026-07-02
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
- CVE-2026-56027CRITICALCVSS 9.9EG 9.92026-06-26
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
- CVE-2026-56058CRITICALCVSS 9.9EG 9.92026-06-26
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
- CVE-2026-56059CRITICALCVSS 9.9EG 9.92026-06-26
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
- CVE-2026-40749CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
- CVE-2026-40748CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
- CVE-2026-40747CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
- CVE-2026-40746CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
- CVE-2026-39589CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
- CVE-2026-27041CRITICALCVSS 9.9EG 9.92026-06-17
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
- CVE-2026-25446CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
- CVE-2026-22327CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.
- CVE-2025-60218CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
- CVE-2024-52488CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
- CVE-2026-40750CRITICALCVSS 9.9EG 9.92026-06-16
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
- CVE-2026-39591CRITICALCVSS 9.9EG 9.92026-06-15
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
- CVE-2026-11839CRITICALCVSS 9.9EG 9.92026-06-11
Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.
- CVE-2026-42748CRITICALCVSS 9.9EG 9.92026-05-27
Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.
- CVE-2026-38526CRITICALCVSS 9.9EG 9.92026-04-14
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2026-32536CRITICALCVSS 9.9EG 9.92026-03-25
Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a through <= 2.08.
- CVE-2026-32523CRITICALCVSS 9.9EG 9.92026-03-25
Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJAM Basic: from n/a through <= 6.9.2.
- CVE-2026-32482CRITICALCVSS 9.9EG 9.92026-03-25
Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.
- CVE-2026-25413CRITICALCVSS 9.9EG 9.92026-03-25
Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.
- CVE-2026-24960CRITICALCVSS 9.9EG 9.92026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.
- CVE-2025-68555CRITICALCVSS 9.9EG 9.92026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through < 2.0.1.
- CVE-2025-68554CRITICALCVSS 9.9EG 9.92026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →