CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Avatar Uploader Project 1Avatar Uploader Jul 24, 2026 May 10, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs...Show more |
1Avatar Uploader Project 1Avatar Uploader May 6, 2026 Feb 26, 2015 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it v...Show more |
1Avatar Uploader Project 1Avatar Uploader May 6, 2026 Dec 1, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path...Show more |