CWE-434


Unrestricted Upload of File with Dangerous Type

The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.


We have discovered 5,338 live websites that are affected by CWE-434.

Contact us to get more info









CVEs

  • Count - 4



Countries

United States1,159 websites



Japan1,737 websites
Germany427 websites
France189 websites
GB182 websites
Italy131 websites
Spain125 websites
Russia122 websites
Poland102 websites
Brazil87 websites

TLDs

.com2,457 websites
.jp346 websites
.de273 websites
.org269 websites
.net256 websites
.co.jp156 websites
.ru99 websites
.co.uk82 websites
.it80 websites
.pl78 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-434
DiscoveredCVEDescriptionWebsites
Feb, 2024CVE-2024-25913 WordPress MoveTo Plugin <= 6.2 is vulnerable to Arbitrary File Upload49
Dec, 2023CVE-2023-34007 WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload1,555
Nov, 2023CVE-2023-5604 Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload228
Nov, 2021CVE-2021-42362 WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload3,512
List of the most common CVEs that are part of CWE-434
DiscoveredCVEDescriptionWebsites
Nov, 2021CVE-2021-42362 WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload3,512
Dec, 2023CVE-2023-34007 WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload1,555
Nov, 2023CVE-2023-5604 Asgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload228
Feb, 2024CVE-2024-25913 WordPress MoveTo Plugin <= 6.2 is vulnerable to Arbitrary File Upload49

Websites affected by CWE-434

Top websites that are affected by CWE-434. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**********.com United States*,***
***************.com United States**,***
*******************.com Japan**,***
********.tokyo Japan**,***
*****.***.**.uk GB**,***
******.com United States**,***
***.***************.com United States**,***
**************.com United States**,***
********.com United States**,***
***.**********.com United States**,***
See full domain list