The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Volume of CVEs assigned to CWE-434 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
4,212 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56290CRITICAL Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitra | Jun 29, 2026 | 9.8 | 99 | YES | YES |
CVE-2020-25213CRITICAL The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder co | Sep 9, 2020 | 9.8 | 99 | YES | YES |
CVE-2018-15961CRITICAL Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation | Sep 25, 2018 | 9.8 | 99 | YES | YES |
CVE-2017-12617HIGH When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation | Oct 4, 2017 | 8.1 | 99 | YES | YES |
CVE-2016-3088CRITICAL The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request. | Jun 1, 2016 | 9.8 | 99 | YES | YES |
CVE-2026-56291CRITICAL Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary f | Jul 9, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-52691CRITICAL Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code | Dec 29, 2025 | 10.0 | 98 | YES | YES |
CVE-2025-31324CRITICAL SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries tha | Apr 24, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-50623CRITICAL In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. | Oct 28, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-7399CRITICAL Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system au | Aug 12, 2024 | 9.8 | 98 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.