Skip to main content

About CWE-434

If the server interprets an uploaded file as code, arbitrary code execution follows. Web server extensions are a particular risk because the server may run them without an execute permission on the file.

MITRE name
Unrestricted Upload of File with Dangerous Type
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft
Also known as
Unrestricted File Upload

Mitigations

  • +Generate a new, unique filename for each upload instead of using the name the user supplied.
  • +Store uploaded files outside the web document root and serve them through a separate mechanism.
  • +Permit only a short list of allowed extensions, allow a single extension per filename, and compare extensions case-insensitively where the server does.
  • +Repeat client-side checks on the server.

Detection
MITRE cites manual source code review and source code weakness analyzers as highly cost effective, with web application scanners and fuzzers giving partial coverage.

CWE-434 Vulnerabilities

15 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-48939
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
icagenda.com10.020.1%KEV2026-06-20
CVE-2026-56291
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
balbooa.com10.014.9%KEV2026-07-09
CVE-2026-48908
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
joomshaper.net10.088.5%KEV2026-06-20
CVE-2026-56290
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
joomlack.fr10.030.9%KEV2026-06-29
CVE-2024-7399
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung Electronics8.891.9%KEV2024-08-09
CVE-2025-2749
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
Kentico7.24.1%KEV2025-03-24
CVE-2024-7694
TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File Upload
TeamT57.21.8%KEV2024-08-12
CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
SAP_SE10.099.5%KEV2025-04-24
CVE-2024-57968
Advantive VeraCore Unrestricted File Upload Vulnerability
Advantive9.932.3%KEV2025-02-03
CVE-2024-50623
Cleo Multiple Products Unrestricted File Upload Vulnerability
-9.898.6%KEV2024-10-27
CVE-2020-8260
Ivanti Pulse Connect Secure Code Execution Vulnerability
-7.296.5%KEV2020-10-28
CVE-2021-20022
SonicWall Email Security Unrestricted Upload of File Vulnerability
SonicWall7.216.6%KEV2021-04-09
CVE-2026-0740
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
SaturdayDrive9.862.9%2026-04-07
CVE-2026-1357
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
wpvividplugins9.833.3%2026-02-11
CVE-2026-3891
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
linknacional9.829.7%2026-03-13

Most Affected Vendors

Frequently Asked Questions

What is CWE-434?→

CWE-434 is the upload of a dangerous file type that the environment later processes automatically, such as a script the web server will execute.

Is checking the file extension enough?→

Not on its own. MITRE also advises generating new filenames, enforcing one extension per name, and storing files outside the web root.

How many exploited vulnerabilities are classified as CWE-434?→

This database lists 15 CVE records mapped to CWE-434 by their CVE Numbering Authority. 12 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-48939, CVE-2026-56291, CVE-2026-48908.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.