CVE-2026-33653
Last modified
CVE-2026-33653 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. An attacker can upload a file with a malicious filename containing JavaScript code, which is later rendered in the application without proper escaping. When the filename is displayed in the file list or file details page, the malicious script executes in the browser of any user who views the page. Version 3.1.2 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Farisc0de | Uploady | < 3.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33653?
How severe is CVE-2026-33653?
How do I fix CVE-2026-33653?
Are you affected by CVE-2026-33653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
