Vulnerabilities > Picuploader Project

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-41442 Cross-site Scripting vulnerability in Picuploader Project Picuploader 2.6.3
PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php.
network
low complexity
picuploader-project CWE-79
6.1
2022-08-30 CVE-2022-36748 Cross-site Scripting vulnerability in Picuploader Project Picuploader 2.6.3
PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php.
network
low complexity
picuploader-project CWE-79
6.1