Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Duckbreast

#43963of 53,625
6.1Total CVSS
Vulnerabilities · 1
PT-2026-30909
6.1
2026-04-07
Quickdrop · Quickdrop · CVE-2026-35608
Name of the Vulnerable Software and Affected Versions QuickDrop versions prior to 1.5.3 Description QuickDrop, a file sharing application, contains a stored cross-site scripting (XSS) issue in the file preview functionality. The application allows the upload of SVG files via the `/api/file/upload-chunk` endpoint. An attacker can upload a crafted SVG file containing a JavaScript payload. When a user views the file preview, the script executes within the application's domain. Recommendations Update to version 1.5.3 or later.