Tad Uploader Project maintains a focused file-upload utility where vulnerabilities center on access control and input-handling deficiencies, including improper authorization, cross-site scripting, and missing authentication barriers on critical functions. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tad Uploader Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41567MEDIUM The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execut | Oct 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-41976MEDIUM Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in | Oct 8, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tad Uploader Project.
Media articles that mention a CVE ID that affects a product developed by Tad Uploader Project — matched by CVE ID, not by vendor name.