Vulnerabilities in filebrowser

61 results
Vexday analysis

O filebrowser apresenta um volume significativo de vulnerabilidades (43 CVEs) com concentração recente: 15 publicadas nos últimos 90 dias. Embora nenhuma esteja sob exploração ativa conhecida, 4 vulnerabilidades críticas foram registradas, sendo a falha de controle de acesso (CWE-863) o padrão dominante. O risco é moderado e em evolução, exigindo monitoramento atento das correções disponibilizadas.

CVE-2026-35585HIGHFile Browser has a Command Injection via Hook RunnerEPSS 2.4%CVE-2026-32759MEDIUMFile Browser TUS Negative Upload-Length Fires Post-Upload Hooks PrematurelyEPSS 2.2%CVE-2025-52903HIGHFile Browser Allows Execution of Shell Commands That Can Spawn Other CommandsEPSS 1.1%CVE-2025-52904HIGHFile Browser: Command Execution not Limited to ScopeEPSS 1.0%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2026-32760CRITICALFile Browser Self Registration Grants Any User Admin Access When Default Permissions Include AdminEPSS 0.7%CVE-2026-34528HIGHFile Browser's Signup Grants Execution Permissions When Default Permissions Includes ExecutionEPSS 0.7%CVE-2026-54089CRITICALFile Browser: Authentication Bypass via Proxy Auth Header ForgeryEPSS 0.6%CVE-2025-52995HIGHFile Browser vulnerable to command execution allowlist bypassEPSS 0.6%CVE-2026-29188CRITICALFile Browser: TUS Delete Endpoint Bypasses Delete Permission CheckEPSS 0.6%CVE-2026-72839CRITICALfilebrowser through 2.63.16 Privilege Escalation via SignupEPSS 0.6%CVE-2026-35607HIGHFile Browser: Proxy auth auto-provisioned users inherit Execute permission and CommandsEPSS 0.6%CVE-2025-52901MEDIUMFile Browser allows sensitive data to be transferred in URLEPSS 0.6%CVE-2026-72837HIGHFile Browser before 2.63.20 Privilege Escalation via Proxy AuthenticationEPSS 0.6%CVE-2026-73613HIGHfilebrowser before 2.63.19 Out-of-Scope File Deletion via SymlinkEPSS 0.6%CVE-2026-62685HIGHFile Browser: Colliding username normalization gives two users the same home directoryEPSS 0.6%CVE-2026-72836CRITICALFileBrowser before 2.63.19 Case Sensitivity Authentication BypassEPSS 0.5%CVE-2026-54092MEDIUMFile Browser: DoS Vulnerability on Public Login APIEPSS 0.5%CVE-2026-25890HIGHFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URLEPSS 0.5%CVE-2026-72838HIGHFileBrowser before 2.63.19 Disk Exhaustion via TUS UploadEPSS 0.5%