VYPR

FileZen

by Soliton

CVEs (5)

  • CVE-2026-25108HigKEVFeb 13, 2026
    risk 0.70cvss 8.8epss 0.05

    FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.

  • CVE-2020-5639CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.05

    Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed.

  • CVE-2018-0694CriNov 15, 2018
    risk 0.64cvss 9.8epss 0.02

    FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-0693HigNov 15, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors.

  • CVE-2021-20655HigFeb 17, 2021
    risk 0.47cvss 7.2epss 0.04

    FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.