TransloaditCVEs & Vulnerabilities
4 CVEs affecting Transloadit products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
uppy 4tusdotnet 1
CVE-2022-0528HIGH
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
3 Mar 2022
7.5
CVSS
CVE-2022-0086CRITICAL
uppy is vulnerable to Server-Side Request Forgery (SSRF)
4 Jan 2022
9.8
CVSS
CVE-2021-44150HIGH
The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.
23 Nov 2021
7.5
CVSS
CVE-2020-8205HIGH
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
20 Jul 2020
7.5
CVSS
← PrevPage 1 / 1Next →