CVE-2026-33653

Source
https://cve.org/CVERecord?id=CVE-2026-33653
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33653.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33653
Aliases
  • GHSA-2834-m7xm-fqr5
Published
2026-03-26T21:00:27.373Z
Modified
2026-04-10T05:43:18.049599Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Uploady Vulnerable to Stored Cross-Site Scripting (XSS)
Details

Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. An attacker can upload a file with a malicious filename containing JavaScript code, which is later rendered in the application without proper escaping. When the filename is displayed in the file list or file details page, the malicious script executes in the browser of any user who views the page. Version 3.1.2 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33653.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/farisc0de/uploady

Affected ranges

Type
GIT
Repo
https://github.com/farisc0de/uploady
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.1.2"
        }
    ]
}

Affected versions

v1.*
v1.5.2
v1.5.3
v2.*
v2.0.0
v2.0.1
v3.*
v3.0.0
v3.0.1
v3.0.10
v3.0.10.1
v3.0.11
v3.0.13.1
v3.0.14
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.6.1
v3.0.6.2
v3.0.7
v3.0.8
v3.0.8.1
v3.0.8.2
v3.0.9
v3.1.0
v3.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33653.json"