Picuploader Project maintains a focused image-upload utility that, despite its narrow scope, appears to be deployed across web applications where user-supplied content handling is required. The observed vulnerability pattern centers on cross-site scripting through improper neutralization of input during web page generation, a characteristic weakness in applications that process and display user-contributed media without sufficient sanitization.
The number and severity of CVEs published that impact products developed by Picuploader Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41442MEDIUM PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php. | Oct 7, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-36748MEDIUM PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php. | Aug 30, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Picuploader Project.
Media articles that mention a CVE ID that affects a product developed by Picuploader Project — matched by CVE ID, not by vendor name.