---
id: CVE-2021-37504
title: >-
  A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of
  jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts
  or HTML via a crafted file with a Javascript payload in the file name.
summary: >-
  A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of
  jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts
  or HTML via a crafted file with a Javascript payload in the file name.
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: hayageek
product: jquery_upload_file
affected:
  - jquery_upload_file = 4.0.11
published: '2022-02-25'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37504'
references:
  - url: 'http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js'
    label: cve@mitre.org
  - url: >-
      http://hayageek.github.io/jQuery-Upload-File/4.0.11/jquery.uploadfile.min.js
    label: cve@mitre.org
  - url: 'http://hayageek.github.io/jQuery-Upload-File/4.0.11/uploadfile.css'
    label: cve@mitre.org
  - url: >-
      https://github.com/hayageek/jquery-upload-file/blob/master/js/jquery.uploadfile.js#L469
    label: cve@mitre.org
  - url: >-
      https://raw.githubusercontent.com/hayageek/jquery-upload-file/master/js/jquery.uploadfile.js
    label: cve@mitre.org
  - url: 'http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://hayageek.github.io/jQuery-Upload-File/4.0.11/jquery.uploadfile.min.js
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://hayageek.github.io/jQuery-Upload-File/4.0.11/uploadfile.css'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://haygeek.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://jquery-upload-file.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/hayageek/jquery-upload-file/blob/master/js/jquery.uploadfile.js#L469
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://raw.githubusercontent.com/hayageek/jquery-upload-file/master/js/jquery.uploadfile.js
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00867
epssPercentile: 0.56916
ingestedAt: '2026-07-06T02:09:23.213Z'
---

## Overview

A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.

## Affected

- `jquery_upload_file = 4.0.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
