CVE-2026-30579

File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:leefish:file_thingie:2.5.7:*:*:*:*:*:*:*

History

01 Apr 2026, 19:01

Type Values Removed Values Added
Summary
  • (es) File Thingie 2.5.7 es vulnerable a Cross Site Scripting (XSS). Un usuario malicioso puede aprovechar la funcionalidad de 'subir archivo' para subir un archivo con un nombre de archivo manipulado utilizado para activar una carga útil de Javascript.
First Time Leefish
Leefish file Thingie
CPE cpe:2.3:a:leefish:file_thingie:2.5.7:*:*:*:*:*:*:*
References () https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-30579 - () https://github.com/SpeWnz/Vulnerability-Research/tree/main/CVE-2026-30579 - Third Party Advisory
References () https://github.com/leefish/filethingie - () https://github.com/leefish/filethingie - Product

23 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 18:16

Updated : 2026-04-01 19:01


NVD link : CVE-2026-30579

Mitre link : CVE-2026-30579

CVE.ORG link : CVE-2026-30579


JSON object : View

Products Affected

leefish

  • file_thingie
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')