Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2021-23562
Disclosure Date: December 03, 2021 (last updated February 23, 2025)
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
0
Attacker Value
Unknown
CVE-2016-4566
Disclosure Date: May 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
0
Attacker Value
Unknown
CVE-2013-0237
Disclosure Date: July 08, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2012-2401
Disclosure Date: April 21, 2012 (last updated October 04, 2023)
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
0