moxiecode/plupload
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 2.3.9 | 4.2 MEDIUM | 6.8 MEDIUM | ||
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file. | ||||
| — | 5.4 MEDIUM | 4.3 MEDIUM | ||
This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed. | ||||
| <= 2.1.8 | — | 4.3 MEDIUM | ||
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack. | ||||
| = 1.5.1, = 1.5.0, = 1.4.2, = 1.4.1, = 1.5.2, <= 1.5.4, = 1.4.3, = 1.4.0, = 1.5.3 | — | 4.3 MEDIUM | ||
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. | ||||
| = 1.5.1, = 1.5.0, = 1.4.1, <= 1.5.3, = 1.5.2, = 1.4.2, = 1.4.0, = 1.4.3 | — | 5 MEDIUM | ||
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content. | ||||