CVE-2020-11712: Open Upload Project Open Upload

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.

Affected products

Published 2020-04-12. Last modified 2026-06-17.