Threadlinqs IntelligenceStart free

Weakness · BaseCWE-434

CWE-434: Unrestricted Upload of File with Dangerous Type

Likelihood of exploit: MediumKEV-linkedBase

As of 2026-10-05, CWE-434 (Unrestricted Upload of File with Dangerous Type) underlies 31 CVEs tracked by Threadlinqs, 5 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 71 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
31Mapped to CWE-434
CISA KEV
5Exploited in the wild
Critical
17CVSS v3 critical CVEs
Threats
71Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-434?

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

CWE-434 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: ASP.NET; Language: PHP; Language: Not Language-Specific; Technology: Web Server.

Source: MITRE CWE (CWE-434 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Confidentiality, Availability — Execute Unauthorized Code or Commands. Arbitrary code execution is possible if an uploaded file is interpreted and executed as code by the recipient. This is especially true for web-server extensions such as .asp and .php because these file types are often treated as automatically executable, even when file system permissions do not specify execution. For example, in Unix environments, programs typically cannot run unless the execute bit is set, but PHP programs may be executed by the web server without directly invoking them on the…

Source: MITRE CWE, common consequences.

How CWE-434 is exploited in the wild

Threadlinqs maps 31 CVEs to CWE-434, published between 2020-09-09 and 2026-09-26. 5 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 17 critical, 5 high, 5 medium. The highest EPSS score in the set is 97.3% (CVE-2020-25213), the modelled probability of exploitation in the next 30 days. 71 tracked threats reference CWE-434 directly or through a CVE it covers; the most recent is “Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)” (2026-10-02). Affected products concentrate in Microsoft (2), N8n (2), SourceCodester (2), among 27 vendors in total.

Vulnerabilities (CVEs)

All 31 CVEs mapped to CWE-434, CISA KEV first, then by CVSS score.

  • CVE-2020-25213 — CISA KEV · CVSS 10 critical · EPSS 97.3% · published 2020-09-09
  • CVE-2025-52691 — CISA KEV · CVSS 10 critical · EPSS 87.2% · published 2025-12-29
  • CVE-2026-48939 — CISA KEV · CVSS 9.8 critical · EPSS 1.5% · published 2026-06-20
  • CVE-2026-56291 — CISA KEV · CVSS 9.8 critical · EPSS 0.8% · published 2026-07-09
  • CVE-2021-31207 — CISA KEV · CVSS 6.6 medium · EPSS 93.8% · published 2021-05-11
  • CVE-2026-48276 — CVSS 10 critical · EPSS 0.9% · published 2026-06-30
  • CVE-2026-21877 — CVSS 9.9 critical · EPSS 14.1% · published 2026-01-08
  • CVE-2026-3844 — CVSS 9.8 critical · EPSS 36.5% · published 2026-04-23
  • CVE-2026-1357 — CVSS 9.8 critical · EPSS 15.8% · published 2026-02-11
  • CVE-2020-36847 — CVSS 9.8 critical · EPSS 12.6% · published 2025-07-12
  • CVE-2024-4345 — CVSS 9.8 critical · EPSS 1.4% · published 2024-05-07
  • CVE-2026-82901 — CVSS 9.8 critical · EPSS 1.1% · published 2026-09-26
  • CVE-2026-93352 — CVSS 9.8 critical · EPSS 0.6% · published 2026-09-23
  • CVE-2026-21536 — CVSS 9.8 critical · EPSS 0.4% · published 2026-03-05
  • CVE-2026-84637 — CVSS 9.8 critical · EPSS 0.1% · published 2026-09-01
  • CVE-2026-15748 — CVSS 9.8 critical · published 2026-08-18
  • CVE-2026-2701 — CVSS 9.1 critical · EPSS 0.2% · published 2026-04-02
  • CVE-2026-27540 — CVSS 9 critical · EPSS 2.3% · published 2026-03-19
  • CVE-2026-25056 — CVSS 8.8 high · EPSS 0.1% · published 2026-02-04
  • CVE-2025-7443 — CVSS 8.1 high · EPSS 0.6% · published 2025-08-01
  • CVE-2026-90603 — CVSS 7.3 high · EPSS 0.4% · published 2026-09-13
  • CVE-2026-82921 — CVSS 7.3 high · EPSS 0.2% · published 2026-08-31
  • CVE-2026-82524 — CVSS 7.2 high · EPSS 0.3% · published 2026-09-02
  • CVE-2026-95820 — CVSS 6.3 medium · EPSS 0.3% · published 2026-09-22
  • CVE-2026-14775 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-05
  • CVE-2026-14776 — CVSS 6.3 medium · EPSS 0.2% · published 2026-07-05
  • CVE-2026-1969 — CVSS 5.3 medium · EPSS 0.1% · published 2026-03-23
  • CVE-2026-57311 — EPSS 0.3% · published 2026-07-20
  • CVE-2026-81931 — EPSS 0.2% · published 2026-08-27
  • CVE-2026-74767 — EPSS 0.2% · published 2026-08-15
  • CVE-2026-61448 — EPSS 0.2% · published 2026-07-11

Affected vendors

  • Microsoft — 2 CVEs
  • N8n — 2 CVEs
  • SourceCodester — 2 CVEs
  • Adobe — 1 CVE
  • Anil-matcha — 1 CVE
  • Filemanagerpro — 1 CVE
  • JCD — 1 CVE
  • Mozilla — 1 CVE
  • Progress — 1 CVE
  • Roskus — 1 CVE
  • Rymera Web Co Pty Ltd. — 1 CVE
  • ShopEx — 1 CVE

Threat activity

71 tracked threats cite CWE-434; the 25 most recent are listed.

Mitigations

  • Architecture and Design: Generate a new, unique filename for an uploaded file instead of using the user-supplied filename, so that no external input is used at all.[REF-422] [REF-423]
  • Architecture and Design / Enforcement by Conversion: When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
  • Architecture and Design: Consider storing the uploaded files outside of the web document root entirely. Then, use other mechanisms to deliver the files dynamically. [REF-423]
  • Implementation / Input Validation: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
  • Architecture and Design: Define a very limited set of allowable extensions and only generate filenames that end in these extensions. Consider the possibility of XSS (CWE-79) before allowing .html or .htm file types.
  • Implementation / Input Validation: Ensure that only one extension is used in the filename. Some web servers, including some versions of Apache, may process files based on inner extensions so that "filename.php.gif" is fed to the PHP interpreter.[REF-422] [REF-423]
  • Implementation: When running on a web server that supports case-insensitive filenames, perform case-insensitive evaluations of the extensions that are provided.
  • Architecture and Design: For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
  • Implementation: Do not rely exclusively on sanity checks of file contents to ensure that the file is of the expected type and size. It may be possible for an attacker to hide code in some file segments that will still be executed by the server. For example, GIF images may contain a free-form comments field.
  • Implementation: Do not rely exclusively on the MIME content type or filename attribute when determining how to render a file. Validating the MIME content type and ensuring that it matches the extension is only a partial solution.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Dynamic Analysis with Automated Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
  • Manual Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
  • Automated Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
  • Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.