📦

swfupload

Vendor: swfupload_project

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 5.03% Exploit Prob.
Latest CVE CVE-2013-4144 Jun 30

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

There is an object injection vulnerability in swfupload plugin for wordpress.

EPSS: 0.98%
4.3 CVSS
CVE-2012-3414
Exploit Found

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

EPSS: 9.09%