Seafile
by Seafile
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-7469 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2019 | Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks. | ||
| CVE-2025-41080 | Med | 0.40 | 6.1 | 0.00 | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'. | ||
| CVE-2025-41079 | Med | 0.40 | 6.1 | 0.00 | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'. | ||
| CVE-2023-28874 | Med | 0.40 | 6.1 | 0.00 | Dec 9, 2023 | The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites. | ||
| CVE-2023-28873 | Med | 0.35 | 5.4 | 0.00 | Dec 9, 2023 | An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor. | ||
| CVE-2021-30146 | Med | 0.35 | 5.4 | 0.01 | Apr 6, 2021 | Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality." | ||
| CVE-2026-56768 | 0.00 | — | 0.00 | Jun 25, 2026 | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download… |
- risk 0.49cvss 7.5epss 0.01
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
- risk 0.40cvss 6.1epss 0.00
A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'.
- risk 0.40cvss 6.1epss 0.00
A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.
- risk 0.40cvss 6.1epss 0.00
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
- risk 0.35cvss 5.4epss 0.00
An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.
- risk 0.35cvss 5.4epss 0.01
Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
- CVE-2026-56768Jun 25, 2026risk 0.00cvss —epss 0.00
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download…