Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Unrestricted File Upload vulnerabilities

CWE-434 · 12 tracked

Unrestricted File Upload (CWE-434) is a recognized software weakness class in the MITRE CWE catalog. The vulnerabilities below are all instances of this pattern.

How it’s exploited

How unrestricted file upload is exploited depends on the specific vulnerability, but every CVE in this class shares the same underlying flaw pattern — which is why the same class of mitigation applies across them.

How to prevent it

Recognizing the unrestricted file upload pattern lets you apply one class of fix across every affected component. Each CVE page below carries specific, version-level remediation.

Tracked unrestricted file upload vulnerabilities

12 CVEs in this class, each with severity, exploit status, EPSS, and remediation.

Frequently asked questions

What is Unrestricted File Upload?
Unrestricted File Upload (CWE-434) is a recognized software weakness class in the MITRE CWE catalog. The vulnerabilities below are all instances of this pattern.
How is unrestricted file upload exploited?
How unrestricted file upload is exploited depends on the specific vulnerability, but every CVE in this class shares the same underlying flaw pattern — which is why the same class of mitigation applies across them.
How do you prevent unrestricted file upload?
Recognizing the unrestricted file upload pattern lets you apply one class of fix across every affected component. Each CVE page below carries specific, version-level remediation.
How many unrestricted file upload vulnerabilities are there?
O3 tracks 12 vulnerabilities classified as CWE-434 (Unrestricted File Upload), each with severity, exploit status, EPSS exploitation probability, and remediation. The full list is below.