Gwtupload Project maintains a file-upload component library for GWT-based web applications, with its vulnerability profile centered on input-handling and file-management weaknesses, notably cross-site scripting and unrestricted file upload flaws. These recur across its core product and reflect the inherent risks of accepting and processing user-supplied content in web-facing contexts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gwtupload Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9447MEDIUM There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaSc | Feb 28, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-13128HIGH An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can | May 18, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gwtupload Project.
Media articles that mention a CVE ID that affects a product developed by Gwtupload Project — matched by CVE ID, not by vendor name.