Unrestricted File Upload (CWE-434)
CWE-434 applies when a product accepts uploads of dangerous file types that its environment then processes automatically. MITRE considers the phrase unrestricted file upload imprecise, because it could also mean missing limits on file size or count, which is a separate resource issue.
About CWE-434
If the server interprets an uploaded file as code, arbitrary code execution follows. Web server extensions are a particular risk because the server may run them without an execute permission on the file.
Mitigations
- +Generate a new, unique filename for each upload instead of using the name the user supplied.
- +Store uploaded files outside the web document root and serve them through a separate mechanism.
- +Permit only a short list of allowed extensions, allow a single extension per filename, and compare extensions case-insensitively where the server does.
- +Repeat client-side checks on the server.
Detection
MITRE cites manual source code review and source code weakness analyzers as highly cost effective, with web application scanners and fuzzers giving partial coverage.
CWE-434 Vulnerabilities
15 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-48939 | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 | icagenda.com | 10.0 | 20.1% | KEV | 2026-06-20 |
| CVE-2026-56291 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 | balbooa.com | 10.0 | 14.9% | KEV | 2026-07-09 |
| CVE-2026-48908 | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 | joomshaper.net | 10.0 | 88.5% | KEV | 2026-06-20 |
| CVE-2026-56290 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 | joomlack.fr | 10.0 | 30.9% | KEV | 2026-06-29 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Samsung Electronics | 8.8 | 91.9% | KEV | 2024-08-09 |
| CVE-2025-2749 | Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE | Kentico | 7.2 | 4.1% | KEV | 2025-03-24 |
| CVE-2024-7694 | TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File Upload | TeamT5 | 7.2 | 1.8% | KEV | 2024-08-12 |
| CVE-2025-31324 | Missing Authorization check in SAP NetWeaver (Visual Composer development server) | SAP_SE | 10.0 | 99.5% | KEV | 2025-04-24 |
| CVE-2024-57968 | Advantive VeraCore Unrestricted File Upload Vulnerability | Advantive | 9.9 | 32.3% | KEV | 2025-02-03 |
| CVE-2024-50623 | Cleo Multiple Products Unrestricted File Upload Vulnerability | - | 9.8 | 98.6% | KEV | 2024-10-27 |
| CVE-2020-8260 | Ivanti Pulse Connect Secure Code Execution Vulnerability | - | 7.2 | 96.5% | KEV | 2020-10-28 |
| CVE-2021-20022 | SonicWall Email Security Unrestricted Upload of File Vulnerability | SonicWall | 7.2 | 16.6% | KEV | 2021-04-09 |
| CVE-2026-0740 | Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload | SaturdayDrive | 9.8 | 62.9% | 2026-04-07 | |
| CVE-2026-1357 | Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload | wpvividplugins | 9.8 | 33.3% | 2026-02-11 | |
| CVE-2026-3891 | Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload | linknacional | 9.8 | 29.7% | 2026-03-13 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-434?→
CWE-434 is the upload of a dangerous file type that the environment later processes automatically, such as a script the web server will execute.
Is checking the file extension enough?→
Not on its own. MITRE also advises generating new filenames, enforcing one extension per name, and storing files outside the web root.
How many exploited vulnerabilities are classified as CWE-434?→
This database lists 15 CVE records mapped to CWE-434 by their CVE Numbering Authority. 12 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-48939, CVE-2026-56291, CVE-2026-48908.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.