VYPR

FileRise

by FileRise

Source repositories

CVEs (4)

  • CVE-2025-68116HigDec 16, 2025
    risk 0.58cvss 8.9epss 0.00

    FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a…

  • CVE-2025-66403MedDec 1, 2025
    risk 0.00cvss 4.6epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG files. The application accepts…

  • CVE-2025-62510HigOct 20, 2025
    risk 0.00cvss 8.1epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inferred from folder names. Low-privilege users could see or interact with folders matching their…

  • CVE-2025-62509HigOct 20, 2025
    risk 0.00cvss 8.1epss 0.00

    FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify) on files…