VYPR
Vendor

Web File Browser

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2020-36973MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using…

  • CVE-2020-36988MedJan 28, 2026
    risk 0.35cvss 5.4epss 0.00

    PDW File Browser version 1.3 contains stored and reflected cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through file rename and path parameters. Attackers can craft malicious URLs or rename files with XSS payloads to execute…

  • CVE-2026-62684lowJul 20, 2026
    risk 0.07cvss epss

    ## Summary When a user creates a password-protected share or lists existing shares, the JSON response includes the full bcrypt `password_hash` and the secret `token` of the share. The `Link` storage struct is serialized directly with `json.Marshal` and tags `password_hash` and…

  • CVE-2007-4921Sep 17, 2007
    risk 0.07cvss epss 0.53

    PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.

  • CVE-2011-4831Dec 15, 2011
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.