Frontend Uploader Project maintains a focused file-upload component for web applications, and its identified vulnerabilities center on cross-site scripting weaknesses arising from improper input neutralization during web page generation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frontend Uploader Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24563MEDIUM The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file con | Oct 11, 2021 | 6.1 | 46 | NO | YES |
CVE-2014-9444MEDIUM Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disall | Jan 2, 2015 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frontend Uploader Project.
Media articles that mention a CVE ID that affects a product developed by Frontend Uploader Project — matched by CVE ID, not by vendor name.