CVE-2021-23562

Arbitrary File Upload

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file.


We have discovered 83,044 live websites that are affected by CVE-2021-23562.

Test my site




Affected Software

Product  Plupload
Category JavaScript Libraries
Vulnerable Domains83,044 live websites (98.77% of Plupload install base)
Vulnerable Versions
  • from 0 before 2.3.9
Vulnerable Versions Count46 versions ( 80.70% of all versions)



Details

  • Published - Dec 3, 2021
  • Updated - Sep 16, 2024

Credits

  • Michele Di Stefano

CVE-2021-23562 usage by Country

United States43,067 websites



Germany8,449 websites
France4,523 websites
GB2,856 websites
Netherlands2,223 websites
Australia1,648 websites
Cyprus1,562 websites
Canada1,265 websites
Bulgaria1,123 websites
Switzerland1,105 websites

CVE-2021-23562 usage by TLD

.com41,333 websites
.org6,746 websites
.de4,184 websites
.com.au2,443 websites
.nl2,341 websites
.co.uk2,153 websites
.net2,053 websites
.fr1,847 websites
.ca1,374 websites
.it1,069 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-23562

Top websites that are affected by CVE-2021-23562. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com United States*,***
***********.com United States*,***
****.net France*,***
*********************.nl Netherlands*,***
***************.com United States*,***
********.com United States*,***
*************.com United States*,***
*********.me United States*,***
*********.********.info United States*,***
*****.org United States*,***
See full domain list

FAQ

A total of 83,044 websites have been identified as vulnerable to CVE-2021-23562, discovered through global website indexing conducted by WebTechSurvey.
Plupload is susceptible to CVE-2021-23562 vulnerability.
Plupload versions before 2.3.9 are vulnerable to CVE-2021-23562.
Version 2.3.9 of Plupload addresses the CVE-2021-23562 security vulnerability.