express-fileupload_project CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

express-fileupload_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all express-fileupload_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk denial of service, with potential vendor impact application crash and vendor impact file overwrite across vendor surface production workloads use cases.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-27261 An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server. [email protected] 7.5 1.32% 2022-04-12 2024-11-21
CVE-2022-27140 An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the express-fileupload middleware is not responsible for an application's business logic (e.g., determining whether or how a file should be renamed). [email protected] 9.8 2.55% 2022-04-12 2024-11-21
CVE-2020-7699 This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution. [email protected] 7.5 4.67% 2020-07-30 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence