File Station
by Synology
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-8923 | Med | 0.42 | 6.5 | 0.01 | Jun 5, 2018 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments. | ||
| CVE-2017-15893 | Med | 0.42 | 6.5 | 0.02 | Dec 8, 2017 | Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter. | ||
| CVE-2025-29843 | Med | 0.35 | 5.4 | 0.00 | Dec 4, 2025 | A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files. | ||
| CVE-2018-13288 | Med | 0.35 | 5.3 | 0.01 | Apr 1, 2019 | Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter. | ||
| CVE-2025-29844 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2025 | A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information. |
- risk 0.42cvss 6.5epss 0.01
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
- risk 0.42cvss 6.5epss 0.02
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parameter.
- risk 0.35cvss 5.4epss 0.00
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
- risk 0.35cvss 5.3epss 0.01
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
- risk 0.28cvss 4.3epss 0.00
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.