We have discovered 3,995,933 live websites that are affected by CWE-434.
![]() | 1,081,146 websites |
![]() | 471,256 websites |
![]() | 275,610 websites |
![]() | 236,328 websites |
![]() | 220,351 websites |
![]() | 143,648 websites |
![]() | 139,300 websites |
![]() | 121,749 websites |
![]() | 107,061 websites |
![]() | 93,761 websites |
.com | 1,580,312 websites |
.de | 232,857 websites |
.it | 160,896 websites |
.org | 150,515 websites |
.ru | 125,033 websites |
.net | 111,218 websites |
.nl | 99,934 websites |
.pl | 97,541 websites |
.co.uk | 96,300 websites |
.fr | 83,419 websites |
Discovered | CVE | Description | Websites |
---|---|---|---|
May, 2025 | CVE-2025-4317 | TheGem <= 5.10.3 - Authenticated (Subscriber+) Arbitrary File Upload | 6,806 |
May, 2025 | CVE-2025-4403 | Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function | 630 |
May, 2025 | CVE-2025-47549 | WordPress BEAF <= 4.6.10 - Arbitrary File Upload Vulnerability | 1,879 |
May, 2025 | CVE-2025-47550 | WordPress Instantio <= 3.3.16 - Arbitrary File Upload Vulnerability | 82 |
May, 2025 | CVE-2024-13418 | Smart Framework <= Multiple Plugins - Authenticated (Subscriber+) Arbitrary File Upload | 20 |
Apr, 2025 | CVE-2025-46264 | WordPress PowerPress Podcasting <= 11.12.5 - Arbitrary File Upload Vulnerability | 1,132 |
Apr, 2025 | CVE-2025-32682 | WordPress MapSVG Lite plugin <= 8.5.34 - Arbitrary File Upload Vulnerability | 46 |
Apr, 2025 | CVE-2025-39538 | WordPress WP-Advanced-Search <= 3.3.9.3 - Arbitrary File Upload Vulnerability | 1 |
Apr, 2025 | CVE-2025-32215 | WordPress Accessibility Suite plugin <= 4.18 - Arbitrary File Upload vulnerability | 17 |
Apr, 2025 | CVE-2025-2525 | Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Upload | 10 |
Discovered | CVE | Description | Websites |
---|---|---|---|
Apr, 2024 | CVE-2024-31210 | PHP file upload bypass via Plugin installer | 2,852,853 |
Dec, 2023 | CVE-2023-47784 | WordPress Slider Revolution Plugin <= 6.6.15 is vulnerable to Arbitrary File Upload | 1,140,002 |
Mar, 2024 | CVE-2023-48777 | WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability | 446,230 |
Mar, 2024 | CVE-2023-39307 | WordPress Avada theme <= 7.11.1 - Authenticated Arbitrary File Upload vulnerability | 111,341 |
Jul, 2024 | CVE-2024-6828 | Redux Framework 4.4.12 - 4.4.17 - Unauthenticated JSON File Upload to Stored Cross-Site Scripting | 27,115 |
Nov, 2021 | CVE-2021-42362 | WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload | 20,749 |
Feb, 2025 | CVE-2025-1128 | Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion | 19,130 |
Dec, 2023 | CVE-2023-46149 | WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Upload | 13,214 |
Apr, 2025 | CVE-2025-32118 | WordPress CMP – Coming Soon & Maintenance plugin <= 4.1.13 - Remote Code Execution (RCE) vulnerability | 8,565 |
Aug, 2024 | CVE-2022-1206 | AdRotate – Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload | 8,529 |
Domain | Country | Rank | Contacts |
---|---|---|---|
***************.org | ![]() | *** | |
************.org | ![]() | *** | |
*****************.com | ![]() | *** | |
****.br | ![]() | *** | |
****.******.com | ![]() | *** | |
*********.com | ![]() | *** | |
***************.org | ![]() | *** | |
******.com | ![]() | *** | |
*****.com | ![]() | *** | |
*******************.com | ![]() | *** |