Vulnerabilities > Frontend Uploader Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-11 | CVE-2021-24563 | Cross-site Scripting vulnerability in Frontend Uploader Project Frontend Uploader 0.9.2/1.3.2 The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | 4.3 |
2015-01-02 | CVE-2014-9444 | Cross-site Scripting vulnerability in Frontend Uploader Project Frontend Uploader 0.9.2 Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI. | 4.3 |