This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.
We have discovered 83,044 live websites that are affected by CVE-2021-23562.
Product | |
Category | JavaScript Libraries |
Vulnerable Domains | 83,044 live websites (98.77% of Plupload install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 46 versions ( 80.70% of all versions) |
![]() | 43,067 websites |
![]() | 8,449 websites |
![]() | 4,523 websites |
![]() | 2,856 websites |
![]() | 2,223 websites |
![]() | 1,648 websites |
![]() | 1,562 websites |
![]() | 1,265 websites |
![]() | 1,123 websites |
![]() | 1,105 websites |
.com | 41,333 websites |
.org | 6,746 websites |
.de | 4,184 websites |
.com.au | 2,443 websites |
.nl | 2,341 websites |
.co.uk | 2,153 websites |
.net | 2,053 websites |
.fr | 1,847 websites |
.ca | 1,374 websites |
.it | 1,069 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***************.com | ![]() | *,*** | |
***********.com | ![]() | *,*** | |
****.net | ![]() | *,*** | |
*********************.nl | ![]() | *,*** | |
***************.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
*********.me | ![]() | *,*** | |
*********.********.info | ![]() | *,*** | |
*****.org | ![]() | *,*** |
FAQ