We have discovered 3,567,171 live websites that are affected by CWE-434.
| 875,466 websites | |
| 349,564 websites | |
| 216,597 websites | |
| 203,491 websites | |
| 195,449 websites | |
| 153,255 websites | |
| 137,625 websites | |
| 110,552 websites | |
| 109,703 websites | |
| 95,531 websites |
| .com | 1,425,670 websites |
| .de | 198,498 websites |
| .it | 148,162 websites |
| .org | 143,532 websites |
| .ru | 112,358 websites |
| .nl | 94,833 websites |
| .net | 92,057 websites |
| .co.uk | 91,103 websites |
| .pl | 83,289 websites |
| .fr | 80,304 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2026 | CVE-2026-32931 | Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE | 9 |
| Apr, 2026 | CVE-2026-33704 | Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint | 9 |
| Apr, 2026 | CVE-2026-2942 | ProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess | 5 |
| Apr, 2026 | CVE-2026-4808 | Gerador de Certificados – DevApps <= 1.3.6 - Authenticated (Administrator+) Arbitrary File Upload | 8 |
| Apr, 2026 | CVE-2026-0740 | Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload | 6,883 |
| Apr, 2026 | CVE-2025-14938 | Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload | 576 |
| Mar, 2026 | CVE-2026-25099 | Remote Code Execution via Unrestricted File Upload in Bludit | 1,299 |
| Mar, 2026 | CVE-2026-3533 | JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import | 15,800 |
| Mar, 2026 | CVE-2026-27043 | WordPress Photography theme < 7.7.6 - Arbitrary File Upload vulnerability | 73 |
| Mar, 2026 | CVE-2026-27540 | WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability | 117 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2024 | CVE-2024-31210 | PHP file upload bypass via Plugin installer | 2,052,469 |
| Dec, 2023 | CVE-2023-6449 | Contact Form 7 <= 5.8.3 - Authenticated (Editor+) Arbitrary File Upload | 1,211,745 |
| Dec, 2023 | CVE-2023-47784 | WordPress Slider Revolution Plugin <= 6.6.15 is vulnerable to Arbitrary File Upload | 861,105 |
| Mar, 2024 | CVE-2023-48777 | WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability | 290,688 |
| Dec, 2025 | CVE-2025-13407 | GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload | 190,406 |
| Nov, 2025 | CVE-2025-12974 | Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload | 181,702 |
| Nov, 2025 | CVE-2025-12352 | Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image' | 175,657 |
| Jun, 2025 | CVE-2025-4102 | Beaver Builder Plugin (Starter Version) <= 2.9.1 - Authenticated (Administrator+) Arbitrary File Upload | 92,501 |
| Feb, 2024 | CVE-2024-1468 | Avada | Website Builder For WordPress & WooCommerce <= 7.11.4 - Authenticated (Contributor+) Arbitrary File Upload | 85,386 |
| Mar, 2024 | CVE-2023-39307 | WordPress Avada theme <= 7.11.1 - Authenticated Arbitrary File Upload vulnerability | 79,738 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *** | ||
| ************.org | *** | ||
| *****************.com | *** | ||
| ****.br | *** | ||
| *****.net | *** | ||
| ***************.org | *** | ||
| *********.com | *** | ||
| ******.com | *** | ||
| **********.com | *** | ||
| *********.net | *** |