CVE-2020-11712: Open Upload Project Open Upload
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.
Affected products
- Open Upload Project Open Upload: up to and including 0.4.3
Published 2020-04-12. Last modified 2026-06-17.