VYPR
Vendor

Plupload

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2016-4566MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.06

    Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

  • CVE-2021-23562MedDec 3, 2021
    risk 0.20cvss 4.2epss 0.01

    This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.