VendorsHayageekjquery_upload_fileall versions
Vulnerabilities

Hayageek hyaGeek jQuery Upload File

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-9207
Arbitrary file upload in jQuery Upload File <= 4.0.2
Published 2018-11-19 · Modified
9.8EPSS 0.035
CVE-2021-37504
A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.
Published 2022-02-25 · Modified
6.1EPSS 0.009