Vulnerabilities > Alist Project > Alist > 2.0.2

DATE CVE VULNERABILITY TITLE RISK
2023-06-07 CVE-2023-33498 Unrestricted Upload of File with Dangerous Type vulnerability in Alist Project Alist
alist <=3.16.3 is vulnerable to Incorrect Access Control.
network
low complexity
alist-project CWE-434
8.8
2022-03-12 CVE-2022-26533 Cross-site Scripting vulnerability in Alist Project Alist
Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
4.3