VYPR
Vendor

Transloadit

Products
2
CVEs
6
Across products
6
Status
Private

Products

2

Recent CVEs

6
  • CVE-2025-70023CriApr 14, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

  • CVE-2020-8135CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.01

    The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.

  • CVE-2022-0086CriJan 4, 2022
    risk 0.57cvss 9.8epss 0.01

    uppy is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2021-44150HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.01

    The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

  • CVE-2022-0528MedMar 3, 2022
    risk 0.35cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

  • CVE-2020-8205HigJul 20, 2020
    risk 0.00cvss 7.5epss 0.01

    The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.