İçeriğe atla
Noroxi

filebrowser kayıtları

filebrowser üreticisine ait 32 yayımlanmış kayıt.

Tüm kayıtlar

32 kayıt
  • CVE-2026-32760
    40Planlayın

    File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin

    KritikCVSS 10,0İstismar yokEPSS %1

    filebrowser · filebrowser19 Mar 2026

  • CVE-2026-34528
    39İzleyin

    File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution

    KritikCVSS 9,8İstismar yokEPSS %1

    filebrowser · filebrowser1 Nis 2026

  • CVE-2021-46398
    37İzleyin

    A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privile

    YüksekCVSS 8,8Kavram kanıtıEPSS %7

    filebrowser · filebrowser4 Şub 2022

  • CVE-2023-39612
    36İzleyin

    A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administ

    KritikCVSS 9,0İstismar yokEPSS %1

    filebrowser · filebrowser15 Eyl 2023

  • CVE-2026-34529
    36İzleyin

    File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file

    KritikCVSS 9,0İstismar yokEPSS %0

    filebrowser · filebrowser1 Nis 2026

  • CVE-2026-35607
    35İzleyin

    File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

    YüksekCVSS 8,8İstismar yokEPSS %1

    filebrowser · filebrowser7 Nis 2026

  • CVE-2025-52903
    32İzleyin

    File Browser Allows Execution of Shell Commands That Can Spawn Other Commands

    YüksekCVSS 8,0İstismar yokEPSS %1

    filebrowser · filebrowser26 Haz 2025

  • CVE-2025-52904
    32İzleyin

    File Browser: Command Execution not Limited to Scope

    YüksekCVSS 8,0İstismar yokEPSS %1

    filebrowser · filebrowser26 Haz 2025

  • CVE-2026-29188
    32İzleyin

    File Browser: TUS Delete Endpoint Bypasses Delete Permission Check

    YüksekCVSS 8,1İstismar yokEPSS %1

    filebrowser · filebrowser5 Mar 2026

  • CVE-2026-25890
    32İzleyin

    File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

    YüksekCVSS 8,1Kavram kanıtıEPSS %1

    filebrowser · filebrowser9 Şub 2026

  • CVE-2026-35604
    32İzleyin

    File Browser share links remain accessible after Share/Download permissions are revoked

    YüksekCVSS 8,2İstismar yokEPSS %0

    filebrowser · filebrowser7 Nis 2026

  • CVE-2026-35585
    31İzleyin

    File Browser has a Command Injection via Hook Runner

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    filebrowser · filebrowser7 Nis 2026

  • CVE-2026-30933
    30İzleyin

    FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info

    YüksekCVSS 7,5İstismar yokEPSS %1

    filebrowser · filebrowser10 Mar 2026

  • CVE-2025-52997
    30İzleyin

    File Browser Insecurely Handles Passwords

    YüksekCVSS 7,5İstismar yokEPSS %1

    filebrowser · filebrowser30 Haz 2025

  • CVE-2025-53826
    30İzleyin

    FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout

    YüksekCVSS 7,7İstismar yokEPSS %1

    filebrowser · filebrowser15 Tem 2025

  • CVE-2025-53893
    30İzleyin

    File Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processing

    YüksekCVSS 7,7İstismar yokEPSS %0

    filebrowser · filebrowser15 Tem 2025

  • CVE-2026-28492
    28İzleyin

    File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory

    YüksekCVSS 7,1İstismar yokEPSS %0

    filebrowser · filebrowser5 Mar 2026

  • CVE-2025-64523
    28İzleyin

    FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function

    YüksekCVSS 7,2İstismar yokEPSS %0

    filebrowser · filebrowser12 Kas 2025

  • CVE-2026-34530
    27İzleyin

    File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection

    OrtaCVSS 6,9İstismar yokEPSS %0

    filebrowser · filebrowser1 Nis 2026

  • CVE-2025-52995
    26İzleyin

    File Browser vulnerable to command execution allowlist bypass

    OrtaCVSS 6,6İstismar yokEPSS %1

    filebrowser · filebrowser30 Haz 2025

  • CVE-2025-52901
    26İzleyin

    File Browser allows sensitive data to be transferred in URL

    OrtaCVSS 6,5İstismar yokEPSS %1

    filebrowser · filebrowser30 Haz 2025

  • CVE-2026-32761
    26İzleyin

    File Browser has an Authorization Policy Bypass in its Public Share Download Flow

    OrtaCVSS 6,5İstismar yokEPSS %0

    filebrowser · filebrowser19 Mar 2026

  • CVE-2026-32758
    26İzleyin

    File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter

    OrtaCVSS 6,5İstismar yokEPSS %0

    filebrowser · filebrowser19 Mar 2026

  • CVE-2026-35605
    25İzleyin

    File Browser has an access rule bypass via HasPrefix without trailing separator in path matching

    OrtaCVSS 6,3İstismar yokEPSS %0

    filebrowser · filebrowser7 Nis 2026

  • CVE-2026-32759
    22İzleyin

    File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely

    OrtaCVSS 5,3İstismar yokEPSS %2

    filebrowser · filebrowser19 Mar 2026