Responsive FileManager
Products
1- 5 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14728 | Cri | 0.73 | 9.8 | 0.77 | Aug 3, 2018 | upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. | ||
| CVE-2020-10567 | Cri | 0.65 | 9.8 | 0.19 | Mar 14, 2020 | An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains… | ||
| CVE-2022-44276 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2023 | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | ||
| CVE-2026-37266 | Hig | 0.52 | 8.0 | 0.00 | May 28, 2026 | An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component | ||
| CVE-2020-11106 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2020 | An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a… |
- risk 0.73cvss 9.8epss 0.77
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
- risk 0.65cvss 9.8epss 0.19
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains…
- risk 0.64cvss 9.8epss 0.02
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
- risk 0.52cvss 8.0epss 0.00
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a…