CWE-434— Unrestricted Upload of File with Dangerous Type
3,928 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 61 of 79
- CVE-2025-10147CRITICALCVSS 9.8EG 9.82025-09-23
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for …
- CVE-2025-1025HIGHCVSS 7.5EG 7.52025-02-05
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
- CVE-2025-1028HIGHCVSS 8.1EG 8.12025-02-05
The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload feature in all versions up to, and including, 8.6.4. This makes it possible for unauthenticated…
- CVE-2025-10371HIGHCVSS 7.3EG 7.32025-09-13
A security flaw has been discovered in eCharge Hardy Barth Salia PLCC up to 2.3.81. This issue affects some unknown processing of the file /api.php. The manipulation of the argument setrfidlist results in unrestricted upload. The attack ma…
- CVE-2025-10398MEDIUMCVSS 6.3EG 6.32025-09-14
A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects unknown code of the file FileUploadUtils.java. The manipulation of the argument File results in unrestricted upload. The …
- CVE-2025-10412CRITICALCVSS 9.8EG 9.82025-09-23
The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'uni_cpo_upload_file' function in all ve…
- CVE-2025-10424HIGHCVSS 7.3EG 7.32025-09-15
A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the a…
- CVE-2025-10425HIGHCVSS 7.3EG 7.32025-09-15
A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the a…
- CVE-2025-10427MEDIUMCVSS 6.3EG 6.32025-09-15
A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/operation/user.php. Executing manipulation of the argument website_image can lead to unrestricted up…
- CVE-2025-10428MEDIUMCVSS 6.3EG 6.32025-09-15
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/seo_setting.php of the component Setting Handler. The manipulation of the argument websit…
- CVE-2025-10447HIGHCVSS 7.3EG 7.32025-09-15
A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform.php. The manipulation of the argument picture results in unrestricted upload. It is possi…
- CVE-2025-10465HIGHCVSS 8.8EG 8.82026-02-09
Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server. This issue affects Sensaway: through 09022026. NOTE: Becaus…
- CVE-2025-10480MEDIUMCVSS 6.3EG 6.32025-09-15
A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched rem…
- CVE-2025-10544HIGHCVSS 8.6EG 0.02025-09-26
Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerabilit…
- CVE-2025-10600HIGHCVSS 7.3EG 7.32025-09-17
A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulation of the argument img causes unrestricted upload. It is possible to initiate the attack re…
- CVE-2025-10615MEDIUMCVSS 6.3EG 6.32025-09-17
A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit is pu…
- CVE-2025-10616MEDIUMCVSS 6.3EG 6.32025-09-17
A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has…
- CVE-2025-10647HIGHCVSS 8.8EG 8.82025-09-19
The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in all versions up to, and including, 1.1.5. This makes it possible …
- CVE-2025-10669MEDIUMCVSS 6.3EG 6.32025-09-18
A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Performing manipulation results in unrestricted upload. It is possible to initiate the attack…
- CVE-2025-1070HIGHCVSS 8.1EG 8.12025-02-13
CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.
- CVE-2025-10741MEDIUMCVSS 6.3EG 6.32025-09-20
A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile Picture Handler. The manipulation of the argument userAvatar leads to unrestricted upload.…
- CVE-2025-10747HIGHCVSS 7.2EG 7.22025-09-26
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated at…
- CVE-2025-10754HIGHCVSS 7.2EG 7.22025-10-15
The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticat…
- CVE-2025-10755MEDIUMCVSS 6.3EG 6.32025-09-20
A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The manipulation of the argument userAvatar results in unrestricted upload. The attack may be pe…
- CVE-2025-10763MEDIUMCVSS 6.3EG 6.32025-09-21
A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by this issue is some unknown functionality of the file /edit-photo of the component Profile Picture Handler. This manipulat…
- CVE-2025-10856HIGHCVSS 8.1EG 8.12026-01-22
Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This issue affects Teknoera: through 01102025.
- CVE-2025-10907HIGHCVSS 8.4EG 8.42025-11-05
An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially craf…
- CVE-2025-1093CRITICALCVSS 9.8EG 9.82025-04-19
The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to u…
- CVE-2025-11020HIGHCVSS 8.8EG 8.82025-10-02
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability in MarkAny SafePC Enterprise on Windows, Linux.Thi…
- CVE-2025-11078MEDIUMCVSS 6.3EG 6.32025-09-27
A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/controller.php?action=photos. The manipulation of the argument photo leads to unr…
- CVE-2025-11103MEDIUMCVSS 4.7EG 4.72025-09-28
A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads t…
- CVE-2025-11136MEDIUMCVSS 4.7EG 4.72025-09-29
A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted …
- CVE-2025-11170CRITICALCVSS 9.8EG 9.82025-11-11
The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import_Controller::import function in all versions up to, and including, 1.0.2. This ma…
- CVE-2025-11221HIGHCVSS 8.8EG 8.82025-10-02
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTONE ChangeFlow allows Path Traversal, Accessing Functionality Not Properly Constrained by AC…
- CVE-2025-1128CRITICALCVSS 9.8EG 9.82025-02-25
The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format'…
- CVE-2025-11318HIGHCVSS 7.3EG 7.32025-10-06
A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The manipulation of …
- CVE-2025-11320MEDIUMCVSS 6.3EG 6.32025-10-06
A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the argume…
- CVE-2025-11347HIGHCVSS 7.3EG 7.32025-10-07
A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Student Page. Performing manipulation result…
- CVE-2025-11351MEDIUMCVSS 6.3EG 6.32025-10-07
A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/editpicexec.php. This manipulation of the argument image causes unrestricted upload. Remote…
- CVE-2025-11352MEDIUMCVSS 6.3EG 6.32025-10-07
A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/addexec.php. Such manipulation of the argument image leads to unrestricted upload. The att…
- CVE-2025-11353MEDIUMCVSS 6.3EG 6.32025-10-07
A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of the file /admin/addgalleryexec.php. Performing manipulation of the argument image results in unrestricted upload. The at…
- CVE-2025-11354MEDIUMCVSS 6.3EG 6.32025-10-07
A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Executing manipulation of the argument image can lead to unrestricted upload. The attack may b…
- CVE-2025-11391CRITICALCVSS 9.8EG 9.82025-10-18
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. …
- CVE-2025-11398MEDIUMCVSS 6.3EG 6.32025-10-07
A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /profile.php of the component Profile Page. Executing manipulation of the argument image can le…
- CVE-2025-11417MEDIUMCVSS 6.3EG 6.32025-10-08
A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/voters_add.php. Executing manipulation of the argument photo can lead to unrestricted uplo…
- CVE-2025-11426MEDIUMCVSS 6.3EG 6.32025-10-08
A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_book.php. The manipulation of the argument image results in unrestric…
- CVE-2025-11436MEDIUMCVSS 6.3EG 6.32025-10-08
A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now…
- CVE-2025-11456CRITICALCVSS 9.8EG 9.82025-11-21
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the eh_crm_new_ticket_post() function in all versions up to, and including, 3.3.1. …
- CVE-2025-11470MEDIUMCVSS 4.7EG 4.72025-10-08
A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function of the file /manage_website.php. The manipulation of the argument website_image/back_logi…
- CVE-2025-11499CRITICALCVSS 9.8EG 9.82025-11-01
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function i…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →