Qiniu Uploader
Qiniu Uploader has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Qiniu Uploader has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2014.
All of these findings were reported by Prajal Kulkarni. Qiniu Uploader is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.5.0.
Qiniu Uploader <= 0.1 - Cross-Site Scripting
Read the full analysisVulnerability Records
Qiniu Uploader
Author
franzcai
You can upload your image to qiniu cloud storage some code refer to the following plugin https://wordpress.org/extend/plugins/dbank-uploader/ Please report bug in https://github.com/caichicong/qiniu-uploader. Thank you. 安装这个插件之后,可以在文章编辑界面点击七牛的图标,上传文件到七牛云储存 部分代码参考了以下插件 https://wordpress.org/extend/plugins/dbank-uploader/ 请到 https://github.com/caichicong/qiniu-uploader 反馈bug. 谢谢 Prerequisite Please install curl extension for php (http://php.net/manual/en/curl.installation.php) Plugin Usage 点击富文本编辑器中的七牛图标,在弹出的窗口中点击upload选择要上传的文件,上传完毕后, 窗口将自动关闭,图片会插入到编辑器相应的位置中。 你可以在 后台管理菜单栏Media (多媒体)下的”七牛云储存”查看已经上传了的文件 todo 图片删除功能 水印添加功能
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C