Vulnerabilities (CVE)

Filtered by vendor Picuploader Project Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41442 1 Picuploader Project 1 Picuploader 2024-11-21 N/A 6.1 MEDIUM
PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php.
CVE-2022-36748 1 Picuploader Project 1 Picuploader 2024-11-21 N/A 6.1 MEDIUM
PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php.