VYPR

Vendor CVEs

Filebrowser

All CVEs

60 total · sorted by risk
  • CVE-2026-72834MedAug 14, 2026
    risk 0.21cvss 4.3epss

    filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and…

  • CVE-2025-52996LowJun 30, 2025
    risk 0.20cvss 3.1epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected…

  • CVE-2026-62683LowJul 15, 2026
    risk 0.00cvss 3.1epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the shared directory is deleted through a path with a trailing…

  • CVE-2026-61874LowJul 12, 2026
    risk 0.00cvss 3.1epss 0.00

    filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same…

  • CVE-2026-55667HigJun 25, 2026
    risk 0.00cvss 8.2epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope…

  • CVE-2026-54089CriJun 25, 2026
    risk 0.00cvss 9.1epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can…

  • CVE-2026-54088CriJun 25, 2026
    risk 0.00cvss epss 0.01

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell…

  • CVE-2023-39612CriSep 16, 2023
    risk 0.00cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.

  • CVE-2021-37794MedAug 31, 2021
    risk 0.00cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger…

  • CVE-2013-2036Jun 24, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."

Page 2 of 2