Vulnerabilities in cloudreve
11 resultsVexday analysis
CloudReve apresenta 10 vulnerabilidades catalogadas, com 9 delas publicadas nos últimos 90 dias, indicando risco recente e acelerado. Nenhuma está sob ataque ativo (KEV) ou classificada como crítica, mas a fraqueza dominante em controle de acesso (CWE-863) pode expor funcionalidades sensíveis. O padrão de divulgação concentrado sugere descobertas recentes que demandam atenção na atualização do software.
CVE-2026-55497MEDIUMCloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)EPSS 0.5%CVE-2022-32167MEDIUMCloudreve - Stored XSSEPSS 0.5%CVE-2026-25726HIGHCloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)EPSS 0.4%CVE-2026-55495MEDIUMCloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner AccountEPSS 0.4%CVE-2026-55496MEDIUMCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicateEPSS 0.4%CVE-2026-55502HIGHCloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentialsEPSS 0.3%CVE-2026-55499MEDIUMCloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipientsEPSS 0.3%CVE-2026-62323MEDIUMCloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignoredEPSS 0.3%CVE-2026-54560HIGHCloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claimEPSS 0.2%CVE-2026-54562MEDIUMCloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responsesEPSS 0.2%CVE-2026-54563HIGHCloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its configured account rootEPSS 0.2%