File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:leefish:file_thingie:2.5.7:*:*:*:*:*:*:* |
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting via Uploaded File Name in File Thingie 2.5.7 |
Mon, 23 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leefish
Leefish file Thingie |
|
| Vendors & Products |
Leefish
Leefish file Thingie |
Fri, 20 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-03-20T00:00:00.000Z
Updated: 2026-03-23T14:07:00.510Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30579
Updated: 2026-03-23T14:06:57.676Z
Status : Analyzed
Published: 2026-03-20T18:16:13.323
Modified: 2026-04-01T19:01:22.010
Link: CVE-2026-30579
No data.