filebrowser records
32 published records for vendor filebrowser.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-269 Improper Privilege Management3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-284 Improper Access Control2
The weakness classes this vendor ships most often: where to look.
CWEAll records
32 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-32760No exploit | File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Adminfilebrowser · filebrowser · CWE-269 | Critical10.0 | — | 0.7% | Mar 19, 2026 |
39Monitor | CVE-2026-34528No exploit | File Browser's Signup Grants Execution Permissions When Default Permissions Includes Executionfilebrowser · filebrowser · CWE-269 | Critical9.8 | — | 0.7% | Apr 1, 2026 |
37Monitor | CVE-2021-46398Proof of concept | A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilefilebrowser · filebrowser · CWE-352 | High8.8 | — | 6.7% | Feb 4, 2022 |
36Monitor | CVE-2023-39612No exploit | A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administfilebrowser · filebrowser · CWE-79 | Critical9.0 | — | 0.9% | Sep 15, 2023 |
36Monitor | CVE-2026-34529No exploit | File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB filefilebrowser · filebrowser · CWE-79 | Critical9.0 | — | 0.4% | Apr 1, 2026 |
35Monitor | CVE-2026-35607No exploit | File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commandsfilebrowser · filebrowser · CWE-269 | High8.8 | — | 0.6% | Apr 7, 2026 |
32Monitor | CVE-2025-52903No exploit | File Browser Allows Execution of Shell Commands That Can Spawn Other Commandsfilebrowser · filebrowser · CWE-77 | High8.0 | — | 1.2% | Jun 26, 2025 |
32Monitor | CVE-2025-52904No exploit | File Browser: Command Execution not Limited to Scopefilebrowser · filebrowser · CWE-77 | High8.0 | — | 1.1% | Jun 26, 2025 |
32Monitor | CVE-2026-29188No exploit | File Browser: TUS Delete Endpoint Bypasses Delete Permission Checkfilebrowser · filebrowser · CWE-284 | High8.1 | — | 0.6% | Mar 5, 2026 |
32Monitor | CVE-2026-25890Proof of concept | File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URLfilebrowser · filebrowser · CWE-706 | High8.1 | — | 0.6% | Feb 9, 2026 |
32Monitor | CVE-2026-35604No exploit | File Browser share links remain accessible after Share/Download permissions are revokedfilebrowser · filebrowser · CWE-863 | High8.2 | — | 0.4% | Apr 7, 2026 |
31Monitor | CVE-2026-35585Proof of concept | File Browser has a Command Injection via Hook Runnerfilebrowser · filebrowser · CWE-78 | High7.5 | — | 2.4% | Apr 7, 2026 |
30Monitor | CVE-2026-30933No exploit | FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/infofilebrowser · filebrowser · CWE-200 | High7.5 | — | 0.5% | Mar 10, 2026 |
30Monitor | CVE-2025-52997No exploit | File Browser Insecurely Handles Passwordsfilebrowser · filebrowser · CWE-307 | High7.5 | — | 0.5% | Jun 30, 2025 |
30Monitor | CVE-2025-53826No exploit | FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logoutfilebrowser · filebrowser · CWE-305 | High7.7 | — | 0.5% | Jul 15, 2025 |
30Monitor | CVE-2025-53893No exploit | File Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processingfilebrowser · filebrowser · CWE-400 | High7.7 | — | 0.4% | Jul 15, 2025 |
28Monitor | CVE-2026-28492No exploit | File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directoryfilebrowser · filebrowser · CWE-200 | High7.1 | — | 0.5% | Mar 5, 2026 |
28Monitor | CVE-2025-64523No exploit | FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Functionfilebrowser · filebrowser · CWE-285 | High7.2 | — | 0.4% | Nov 12, 2025 |
27Monitor | CVE-2026-34530No exploit | File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injectionfilebrowser · filebrowser · CWE-79 | Medium6.9 | — | 0.4% | Apr 1, 2026 |
26Monitor | CVE-2025-52995No exploit | File Browser vulnerable to command execution allowlist bypassfilebrowser · filebrowser · CWE-77 | Medium6.6 | — | 0.6% | Jun 30, 2025 |
26Monitor | CVE-2025-52901No exploit | File Browser allows sensitive data to be transferred in URLfilebrowser · filebrowser · CWE-598 | Medium6.5 | — | 0.6% | Jun 30, 2025 |
26Monitor | CVE-2026-32761No exploit | File Browser has an Authorization Policy Bypass in its Public Share Download Flowfilebrowser · filebrowser · CWE-284 | Medium6.5 | — | 0.5% | Mar 19, 2026 |
26Monitor | CVE-2026-32758No exploit | File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameterfilebrowser · filebrowser · CWE-22 | Medium6.5 | — | 0.4% | Mar 19, 2026 |
25Monitor | CVE-2026-35605No exploit | File Browser has an access rule bypass via HasPrefix without trailing separator in path matchingfilebrowser · filebrowser · CWE-22 | Medium6.3 | — | 0.4% | Apr 7, 2026 |
22Monitor | CVE-2026-32759No exploit | File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurelyfilebrowser · filebrowser · CWE-190 | Medium5.3 | — | 2.2% | Mar 19, 2026 |
- CVE-2026-3276040Plan
File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
CriticalCVSS 10.0No exploitEPSS 1%filebrowser · filebrowserMar 19, 2026
- CVE-2026-3452839Monitor
File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution
CriticalCVSS 9.8No exploitEPSS 1%filebrowser · filebrowserApr 1, 2026
- CVE-2021-4639837Monitor
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privile
HighCVSS 8.8Proof of conceptEPSS 7%filebrowser · filebrowserFeb 4, 2022
- CVE-2023-3961236Monitor
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administ
CriticalCVSS 9.0No exploitEPSS 1%filebrowser · filebrowserSep 15, 2023
- CVE-2026-3452936Monitor
File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
CriticalCVSS 9.0No exploitEPSS 0%filebrowser · filebrowserApr 1, 2026
- CVE-2026-3560735Monitor
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
HighCVSS 8.8No exploitEPSS 1%filebrowser · filebrowserApr 7, 2026
- CVE-2025-5290332Monitor
File Browser Allows Execution of Shell Commands That Can Spawn Other Commands
HighCVSS 8.0No exploitEPSS 1%filebrowser · filebrowserJun 26, 2025
- CVE-2025-5290432Monitor
File Browser: Command Execution not Limited to Scope
HighCVSS 8.0No exploitEPSS 1%filebrowser · filebrowserJun 26, 2025
- CVE-2026-2918832Monitor
File Browser: TUS Delete Endpoint Bypasses Delete Permission Check
HighCVSS 8.1No exploitEPSS 1%filebrowser · filebrowserMar 5, 2026
- CVE-2026-2589032Monitor
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
HighCVSS 8.1Proof of conceptEPSS 1%filebrowser · filebrowserFeb 9, 2026
- CVE-2026-3560432Monitor
File Browser share links remain accessible after Share/Download permissions are revoked
HighCVSS 8.2No exploitEPSS 0%filebrowser · filebrowserApr 7, 2026
- CVE-2026-3558531Monitor
File Browser has a Command Injection via Hook Runner
HighCVSS 7.5Proof of conceptEPSS 2%filebrowser · filebrowserApr 7, 2026
- CVE-2026-3093330Monitor
FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info
HighCVSS 7.5No exploitEPSS 1%filebrowser · filebrowserMar 10, 2026
- CVE-2025-5299730Monitor
File Browser Insecurely Handles Passwords
HighCVSS 7.5No exploitEPSS 1%filebrowser · filebrowserJun 30, 2025
- CVE-2025-5382630Monitor
FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout
HighCVSS 7.7No exploitEPSS 1%filebrowser · filebrowserJul 15, 2025
- CVE-2025-5389330Monitor
File Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processing
HighCVSS 7.7No exploitEPSS 0%filebrowser · filebrowserJul 15, 2025
- CVE-2026-2849228Monitor
File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory
HighCVSS 7.1No exploitEPSS 0%filebrowser · filebrowserMar 5, 2026
- CVE-2025-6452328Monitor
FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function
HighCVSS 7.2No exploitEPSS 0%filebrowser · filebrowserNov 12, 2025
- CVE-2026-3453027Monitor
File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection
MediumCVSS 6.9No exploitEPSS 0%filebrowser · filebrowserApr 1, 2026
- CVE-2025-5299526Monitor
File Browser vulnerable to command execution allowlist bypass
MediumCVSS 6.6No exploitEPSS 1%filebrowser · filebrowserJun 30, 2025
- CVE-2025-5290126Monitor
File Browser allows sensitive data to be transferred in URL
MediumCVSS 6.5No exploitEPSS 1%filebrowser · filebrowserJun 30, 2025
- CVE-2026-3276126Monitor
File Browser has an Authorization Policy Bypass in its Public Share Download Flow
MediumCVSS 6.5No exploitEPSS 0%filebrowser · filebrowserMar 19, 2026
- CVE-2026-3275826Monitor
File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
MediumCVSS 6.5No exploitEPSS 0%filebrowser · filebrowserMar 19, 2026
- CVE-2026-3560525Monitor
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
MediumCVSS 6.3No exploitEPSS 0%filebrowser · filebrowserApr 7, 2026
- CVE-2026-3275922Monitor
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
MediumCVSS 5.3No exploitEPSS 2%filebrowser · filebrowserMar 19, 2026