filebrowser kayıtları
filebrowser üreticisine ait 32 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %87,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-284 Improper Access Control2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
32 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-32760İstismar yok | File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Adminfilebrowser · filebrowser · CWE-269 | Kritik10,0 | — | %0,7 | 19 Mar 2026 |
39İzleyin | CVE-2026-34528İstismar yok | File Browser's Signup Grants Execution Permissions When Default Permissions Includes Executionfilebrowser · filebrowser · CWE-269 | Kritik9,8 | — | %0,7 | 1 Nis 2026 |
37İzleyin | CVE-2021-46398Kavram kanıtı | A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilefilebrowser · filebrowser · CWE-352 | Yüksek8,8 | — | %6,7 | 4 Şub 2022 |
36İzleyin | CVE-2023-39612İstismar yok | A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administfilebrowser · filebrowser · CWE-79 | Kritik9,0 | — | %0,9 | 15 Eyl 2023 |
36İzleyin | CVE-2026-34529İstismar yok | File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB filefilebrowser · filebrowser · CWE-79 | Kritik9,0 | — | %0,4 | 1 Nis 2026 |
35İzleyin | CVE-2026-35607İstismar yok | File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commandsfilebrowser · filebrowser · CWE-269 | Yüksek8,8 | — | %0,6 | 7 Nis 2026 |
32İzleyin | CVE-2025-52903İstismar yok | File Browser Allows Execution of Shell Commands That Can Spawn Other Commandsfilebrowser · filebrowser · CWE-77 | Yüksek8,0 | — | %1,2 | 26 Haz 2025 |
32İzleyin | CVE-2025-52904İstismar yok | File Browser: Command Execution not Limited to Scopefilebrowser · filebrowser · CWE-77 | Yüksek8,0 | — | %1,1 | 26 Haz 2025 |
32İzleyin | CVE-2026-29188İstismar yok | File Browser: TUS Delete Endpoint Bypasses Delete Permission Checkfilebrowser · filebrowser · CWE-284 | Yüksek8,1 | — | %0,6 | 5 Mar 2026 |
32İzleyin | CVE-2026-25890Kavram kanıtı | File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URLfilebrowser · filebrowser · CWE-706 | Yüksek8,1 | — | %0,6 | 9 Şub 2026 |
32İzleyin | CVE-2026-35604İstismar yok | File Browser share links remain accessible after Share/Download permissions are revokedfilebrowser · filebrowser · CWE-863 | Yüksek8,2 | — | %0,4 | 7 Nis 2026 |
31İzleyin | CVE-2026-35585Kavram kanıtı | File Browser has a Command Injection via Hook Runnerfilebrowser · filebrowser · CWE-78 | Yüksek7,5 | — | %2,4 | 7 Nis 2026 |
30İzleyin | CVE-2026-30933İstismar yok | FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/infofilebrowser · filebrowser · CWE-200 | Yüksek7,5 | — | %0,5 | 10 Mar 2026 |
30İzleyin | CVE-2025-52997İstismar yok | File Browser Insecurely Handles Passwordsfilebrowser · filebrowser · CWE-307 | Yüksek7,5 | — | %0,5 | 30 Haz 2025 |
30İzleyin | CVE-2025-53826İstismar yok | FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logoutfilebrowser · filebrowser · CWE-305 | Yüksek7,7 | — | %0,5 | 15 Tem 2025 |
30İzleyin | CVE-2025-53893İstismar yok | File Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processingfilebrowser · filebrowser · CWE-400 | Yüksek7,7 | — | %0,4 | 15 Tem 2025 |
28İzleyin | CVE-2026-28492İstismar yok | File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directoryfilebrowser · filebrowser · CWE-200 | Yüksek7,1 | — | %0,5 | 5 Mar 2026 |
28İzleyin | CVE-2025-64523İstismar yok | FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Functionfilebrowser · filebrowser · CWE-285 | Yüksek7,2 | — | %0,4 | 12 Kas 2025 |
27İzleyin | CVE-2026-34530İstismar yok | File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injectionfilebrowser · filebrowser · CWE-79 | Orta6,9 | — | %0,4 | 1 Nis 2026 |
26İzleyin | CVE-2025-52995İstismar yok | File Browser vulnerable to command execution allowlist bypassfilebrowser · filebrowser · CWE-77 | Orta6,6 | — | %0,6 | 30 Haz 2025 |
26İzleyin | CVE-2025-52901İstismar yok | File Browser allows sensitive data to be transferred in URLfilebrowser · filebrowser · CWE-598 | Orta6,5 | — | %0,6 | 30 Haz 2025 |
26İzleyin | CVE-2026-32761İstismar yok | File Browser has an Authorization Policy Bypass in its Public Share Download Flowfilebrowser · filebrowser · CWE-284 | Orta6,5 | — | %0,5 | 19 Mar 2026 |
26İzleyin | CVE-2026-32758İstismar yok | File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameterfilebrowser · filebrowser · CWE-22 | Orta6,5 | — | %0,4 | 19 Mar 2026 |
25İzleyin | CVE-2026-35605İstismar yok | File Browser has an access rule bypass via HasPrefix without trailing separator in path matchingfilebrowser · filebrowser · CWE-22 | Orta6,3 | — | %0,4 | 7 Nis 2026 |
22İzleyin | CVE-2026-32759İstismar yok | File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurelyfilebrowser · filebrowser · CWE-190 | Orta5,3 | — | %2,2 | 19 Mar 2026 |
- CVE-2026-3276040Planlayın
File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
KritikCVSS 10,0İstismar yokEPSS %1filebrowser · filebrowser19 Mar 2026
- CVE-2026-3452839İzleyin
File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution
KritikCVSS 9,8İstismar yokEPSS %1filebrowser · filebrowser1 Nis 2026
- CVE-2021-4639837İzleyin
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privile
YüksekCVSS 8,8Kavram kanıtıEPSS %7filebrowser · filebrowser4 Şub 2022
- CVE-2023-3961236İzleyin
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administ
KritikCVSS 9,0İstismar yokEPSS %1filebrowser · filebrowser15 Eyl 2023
- CVE-2026-3452936İzleyin
File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
KritikCVSS 9,0İstismar yokEPSS %0filebrowser · filebrowser1 Nis 2026
- CVE-2026-3560735İzleyin
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
YüksekCVSS 8,8İstismar yokEPSS %1filebrowser · filebrowser7 Nis 2026
- CVE-2025-5290332İzleyin
File Browser Allows Execution of Shell Commands That Can Spawn Other Commands
YüksekCVSS 8,0İstismar yokEPSS %1filebrowser · filebrowser26 Haz 2025
- CVE-2025-5290432İzleyin
File Browser: Command Execution not Limited to Scope
YüksekCVSS 8,0İstismar yokEPSS %1filebrowser · filebrowser26 Haz 2025
- CVE-2026-2918832İzleyin
File Browser: TUS Delete Endpoint Bypasses Delete Permission Check
YüksekCVSS 8,1İstismar yokEPSS %1filebrowser · filebrowser5 Mar 2026
- CVE-2026-2589032İzleyin
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
YüksekCVSS 8,1Kavram kanıtıEPSS %1filebrowser · filebrowser9 Şub 2026
- CVE-2026-3560432İzleyin
File Browser share links remain accessible after Share/Download permissions are revoked
YüksekCVSS 8,2İstismar yokEPSS %0filebrowser · filebrowser7 Nis 2026
- CVE-2026-3558531İzleyin
File Browser has a Command Injection via Hook Runner
YüksekCVSS 7,5Kavram kanıtıEPSS %2filebrowser · filebrowser7 Nis 2026
- CVE-2026-3093330İzleyin
FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info
YüksekCVSS 7,5İstismar yokEPSS %1filebrowser · filebrowser10 Mar 2026
- CVE-2025-5299730İzleyin
File Browser Insecurely Handles Passwords
YüksekCVSS 7,5İstismar yokEPSS %1filebrowser · filebrowser30 Haz 2025
- CVE-2025-5382630İzleyin
FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout
YüksekCVSS 7,7İstismar yokEPSS %1filebrowser · filebrowser15 Tem 2025
- CVE-2025-5389330İzleyin
File Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processing
YüksekCVSS 7,7İstismar yokEPSS %0filebrowser · filebrowser15 Tem 2025
- CVE-2026-2849228İzleyin
File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory
YüksekCVSS 7,1İstismar yokEPSS %0filebrowser · filebrowser5 Mar 2026
- CVE-2025-6452328İzleyin
FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function
YüksekCVSS 7,2İstismar yokEPSS %0filebrowser · filebrowser12 Kas 2025
- CVE-2026-3453027İzleyin
File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection
OrtaCVSS 6,9İstismar yokEPSS %0filebrowser · filebrowser1 Nis 2026
- CVE-2025-5299526İzleyin
File Browser vulnerable to command execution allowlist bypass
OrtaCVSS 6,6İstismar yokEPSS %1filebrowser · filebrowser30 Haz 2025
- CVE-2025-5290126İzleyin
File Browser allows sensitive data to be transferred in URL
OrtaCVSS 6,5İstismar yokEPSS %1filebrowser · filebrowser30 Haz 2025
- CVE-2026-3276126İzleyin
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
OrtaCVSS 6,5İstismar yokEPSS %0filebrowser · filebrowser19 Mar 2026
- CVE-2026-3275826İzleyin
File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
OrtaCVSS 6,5İstismar yokEPSS %0filebrowser · filebrowser19 Mar 2026
- CVE-2026-3560525İzleyin
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
OrtaCVSS 6,3İstismar yokEPSS %0filebrowser · filebrowser7 Nis 2026
- CVE-2026-3275922İzleyin
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
OrtaCVSS 5,3İstismar yokEPSS %2filebrowser · filebrowser19 Mar 2026