PT-2026-28506 · Ulloady · Ulloady

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2026-33653

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ulloady versions prior to 3.1.2
Description Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) issue exists because filenames are not properly sanitized during file uploads. An attacker can upload a file with a malicious filename containing JavaScript code. This code is then rendered in the application without proper escaping. When the filename is displayed in the file list or file details page, the malicious script executes in the browser of any user who views the page.
Recommendations Update to Ulloady version 3.1.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33653
GHSA-2834-M7XM-FQR5

Affected Products

Ulloady