| Arbitrary File Upload | |
| Cross-site Scripting (XSS) | |
| URL Redirection to Untrusted Site ('Open Redirect') | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Arbitrary Code Injection | |
| Access Restriction Bypass | |
| Remote Code Execution (RCE) | >=1.0.469, <1.0.470>=1.1.0, <1.1.1 |
| Cross-site Scripting (XSS) | |
| Privilege Escalation | |
| Remote Code Execution (RCE) | |
| Arbitrary File Read | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Arbitrary File Read | |
| Cross-site Scripting (XSS) | |
| Arbitrary File Upload | |
| Arbitrary File Write | |
| Command Injection | |
| Arbitrary Code Execution | |
| Cross-site Scripting (XSS) | |
| File Path Modification | |
| Arbitrary Code Execution | |
| Arbitrary Code Injection | |
| Cross-site Scripting (XSS) | |
| Arbitrary Code Execution | |
| Cross-site Request Forgery (CSRF) | |
| Cross-site Scripting (XSS) | |
| Configuration Modification | |