filerise kayıtları
filerise üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %83,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-280 Improper Handling of Insufficient Permissions or Privileges2
- CWE-863 Incorrect Authorization2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2026-33071İstismar yok | FileRise: WebDAV upload path bypasses filename validation enforced by regular uploadsfilerise · filerise · CWE-434 | Yüksek8,8 | — | %0,7 | 20 Mar 2026 |
32İzleyin | CVE-2026-33329İstismar yok | FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oraclefilerise · filerise · CWE-22 | Yüksek8,1 | — | %0,6 | 24 Mar 2026 |
32İzleyin | CVE-2025-62509İstismar yok | FileRise improper ownership/permission validation allowed cross-tenant file operationsfilerise · filerise · CWE-280 | Yüksek8,1 | — | %0,3 | 20 Eki 2025 |
32İzleyin | CVE-2025-62510İstismar yok | FileRise insecure folder visibility via name-based mapping and incomplete ACL checksfilerise · filerise · CWE-280 | Yüksek8,1 | — | %0,3 | 20 Eki 2025 |
30İzleyin | CVE-2026-25231Kavram kanıtı | FileRise affected by an Unauthenticated File Read Due to Insufficient Access Controlfilerise · filerise · CWE-284 | Yüksek7,5 | — | %1,6 | 9 Şub 2026 |
30İzleyin | CVE-2026-33072İstismar yok | FileRise: Default Encryption Key Enables Token Forgery and Config Decryptionfilerise · filerise · CWE-798 | Yüksek7,5 | — | %0,2 | 20 Mar 2026 |
28İzleyin | CVE-2026-33330İstismar yok | FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callbackfilerise · filerise · CWE-863 | Yüksek7,1 | — | %0,4 | 24 Mar 2026 |
21İzleyin | CVE-2025-68116Kavram kanıtı | FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handlingfilerise · filerise · CWE-79 | Orta5,4 | — | %0,3 | 16 Ara 2025 |
21İzleyin | CVE-2026-25230İstismar yok | FileRise affected by HTML Injection using color property in file tagsfilerise · filerise · CWE-79 | Orta5,4 | — | %0,2 | 9 Şub 2026 |
21İzleyin | CVE-2025-66403İstismar yok | FileRise Vulnerable to Stored XSS via SVG Uploadfilerise · filerise · CWE-79 | Orta5,4 | — | %0,2 | 1 Ara 2025 |
19İzleyin | CVE-2026-33070İstismar yok | FileRise has Unauthenticated Share Link Deletionfilerise · filerise · CWE-306 | Orta4,8 | — | %0,3 | 20 Mar 2026 |
17İzleyin | CVE-2026-33477İstismar yok | FileRise has incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file contentfilerise · filerise · CWE-863 | Orta4,3 | — | %0,3 | 26 Mar 2026 |
- CVE-2026-3307135İzleyin
FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads
YüksekCVSS 8,8İstismar yokEPSS %1filerise · filerise20 Mar 2026
- CVE-2026-3332932İzleyin
FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle
YüksekCVSS 8,1İstismar yokEPSS %1filerise · filerise24 Mar 2026
- CVE-2025-6250932İzleyin
FileRise improper ownership/permission validation allowed cross-tenant file operations
YüksekCVSS 8,1İstismar yokEPSS %0filerise · filerise20 Eki 2025
- CVE-2025-6251032İzleyin
FileRise insecure folder visibility via name-based mapping and incomplete ACL checks
YüksekCVSS 8,1İstismar yokEPSS %0filerise · filerise20 Eki 2025
- CVE-2026-2523130İzleyin
FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control
YüksekCVSS 7,5Kavram kanıtıEPSS %2filerise · filerise9 Şub 2026
- CVE-2026-3307230İzleyin
FileRise: Default Encryption Key Enables Token Forgery and Config Decryption
YüksekCVSS 7,5İstismar yokEPSS %0filerise · filerise20 Mar 2026
- CVE-2026-3333028İzleyin
FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback
YüksekCVSS 7,1İstismar yokEPSS %0filerise · filerise24 Mar 2026
- CVE-2025-6811621İzleyin
FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling
OrtaCVSS 5,4Kavram kanıtıEPSS %0filerise · filerise16 Ara 2025
- CVE-2026-2523021İzleyin
FileRise affected by HTML Injection using color property in file tags
OrtaCVSS 5,4İstismar yokEPSS %0filerise · filerise9 Şub 2026
- CVE-2025-6640321İzleyin
FileRise Vulnerable to Stored XSS via SVG Upload
OrtaCVSS 5,4İstismar yokEPSS %0filerise · filerise1 Ara 2025
- CVE-2026-3307019İzleyin
FileRise has Unauthenticated Share Link Deletion
OrtaCVSS 4,8İstismar yokEPSS %0filerise · filerise20 Mar 2026
- CVE-2026-3347717İzleyin
FileRise has incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file content
OrtaCVSS 4,3İstismar yokEPSS %0filerise · filerise26 Mar 2026