CVE-2026-33653 identifies a Stored Cross-Site Scripting (XSS) vulnerability in Ulloady file uploader script versions prior to 3.1.2, caused by insufficient sanitization of filenames during the upload process. This medium-severity flaw (CVSS 4.6) allows an authenticated attacker to upload a file with a malicious filename, leading to JavaScript execution in the browser of any user who views the affected file list. The potential impact includes limited confidentiality and integrity compromise, such as session hijacking or data theft. Currently, there is no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.2CPE matchmatch criteria | cpe:2.3:a:farisc0de:uploady:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.