Cyber Posture

CWE · MITRE source

CWE-434Unrestricted Upload of File with Dangerous Type

Abstraction: Base · CVEs in our corpus: 4,022

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (4)AI

Control Title Family Why it addresses this CWE
SC-44Detonation ChambersSCDangerous file uploads can be detonated in the chamber to determine malice before any production write or execution occurs.
SC-51Hardware-based ProtectionSCPrevents unrestricted writing of arbitrary or malicious firmware by keeping hardware write-protect enabled except under tightly controlled manual procedures.
MP-7Media UseMPRequiring identifiable owners for portable devices reduces the attack surface for unrestricted uploads of dangerous file types via anonymous media.
SI-3Malicious Code ProtectionSIScans files from external sources on download/open/execute, blocking unrestricted uploads of dangerous file types.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-25213 KEV9.710.00.94422020-09-09
CVE-2016-3088 KEV9.69.80.94232016-06-01
CVE-2017-11357 KEV9.69.80.93682017-08-23
CVE-2018-15961 KEV9.69.80.94422018-09-25
CVE-2024-50623 KEV9.69.80.94012024-10-28
CVE-2017-12615 KEV9.38.10.94202017-09-19
CVE-2017-12617 KEV9.38.10.94362017-10-04
CVE-2025-52691 KEV9.210.00.86402025-12-29
CVE-2021-31207 KEV9.06.60.93842021-05-11
CVE-2019-8394 KEV8.66.50.87522019-02-17
CVE-2021-26828 KEV8.68.80.80022021-06-11
CVE-2024-7399 KEV8.68.80.81302024-08-12
CVE-2020-8260 KEV8.07.20.75892020-10-28
CVE-2020-241867.710.00.94212020-08-24
CVE-2018-92067.69.80.93652018-10-11
CVE-2020-128007.69.80.93882020-06-08
CVE-2020-288717.69.80.93922021-02-10
CVE-2021-244997.69.80.93942021-08-09
CVE-2023-53607.69.80.93482023-10-31
CVE-2023-514097.610.00.92912024-04-12
CVE-2024-50847.69.80.93232024-05-23
CVE-2014-87397.59.80.91552020-02-08
CVE-2021-33787.59.80.92852021-02-01
CVE-2021-363567.59.80.93002021-08-31
CVE-2021-250037.59.80.91582022-03-14