VYPR

filegator

by Filegator

Source repositories

CVEs (3)

  • CVE-2026-63358HigJul 21, 2026
    risk 0.47cvss 7.3epss 0.00

    FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validation. This allows an authenticated user with 'chmod' permission to upgrade their…

  • CVE-2022-1850HigMay 24, 2022
    risk 0.46cvss 8.1epss 0.01

    Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.

  • CVE-2022-1849MedMay 24, 2022
    risk 0.28cvss 5.4epss 0.01

    Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.