tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
CVE-2026-75331
NONE
Updated Aug 27, 2026
Java
n/a:n/a
CVE Details
CVE ID
CVE-2026-75331
Published Date
Aug 27, 2026
Vendor
Java
Severity
NONE
Impact
Minimal impact
Source
View Advisory