Releases41
Frequency3 months 2 weeks
Last Release
Stars5.62K
Plupload is JavaScript API for building file uploaders. It supports multiple file selection, file filtering, chunked upload, client side image downsizing and when necessary can fallback to alternative runtimes, like Flash and Silverlight.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 2.3.94.2 MEDIUM6.8 MEDIUM

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.

5.4 MEDIUM4.3 MEDIUM

This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.

<= 2.1.84.3 MEDIUM

Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.

= 1.5.1, = 1.5.0, = 1.4.2, = 1.4.1, = 1.5.2, <= 1.5.4, = 1.4.3, = 1.4.0, = 1.5.34.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

= 1.5.1, = 1.5.0, = 1.4.1, <= 1.5.3, = 1.5.2, = 1.4.2, = 1.4.0, = 1.4.35 MEDIUM

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.