Express Fileupload is a Node.js middleware library focused on handling file uploads in Express-based web applications, operating in a narrowly scoped but widely embedded role across numerous downstream projects. The observed vulnerabilities reflect the file-handling and input-validation demands of upload processing. Current exploitation activity, severity levels, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Express Fileupload Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7699CRITICAL This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execu | Jul 30, 2020 | 9.8 | 32 | NO | NO |
CVE-2022-27140CRITICAL An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's p | Apr 12, 2022 | 9.8 | 25 | NO | NO |
CVE-2022-27261HIGH An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web applicatio | Apr 12, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Express Fileupload Project.
Media articles that mention a CVE ID that affects a product developed by Express Fileupload Project — matched by CVE ID, not by vendor name.