Vulnerabilities in filebrowser

61 results
Vexday analysis

O filebrowser apresenta um volume significativo de vulnerabilidades (43 CVEs) com concentração recente: 15 publicadas nos últimos 90 dias. Embora nenhuma esteja sob exploração ativa conhecida, 4 vulnerabilidades críticas foram registradas, sendo a falha de controle de acesso (CWE-863) o padrão dominante. O risco é moderado e em evolução, exigindo monitoramento atento das correções disponibilizadas.

CVE-2025-52997MEDIUMFile Browser Insecurely Handles PasswordsEPSS 0.5%CVE-2026-54091HIGHFile Browser: Incorrect access control in public directory shares via rule path rebasingEPSS 0.5%CVE-2026-82235HIGHfilebrowser through 2.63.23 Denial of Service via named pipesEPSS 0.5%CVE-2026-54094HIGHFile Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scopeEPSS 0.5%CVE-2025-53826HIGHFileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after LogoutEPSS 0.5%CVE-2026-90930HIGHFile Browser through 2.63.23 Path Traversal via Symlink AliasEPSS 0.5%CVE-2026-72835HIGHfilebrowser before v2.63.21 Access Rule Bypass via Path CanonicalizationEPSS 0.5%CVE-2026-55667HIGHFile Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanupEPSS 0.5%CVE-2026-23849MEDIUMFile Browser vulnerable to Username Enumeration via Timing Attack in /api/loginEPSS 0.5%CVE-2026-73612HIGHFile Browser before v2.63.22 Authorization Bypass via Recursive OperationsEPSS 0.5%CVE-2026-28492HIGHFile Browser: Path Traversal in Public Share Links Exposes Files Outside Shared DirectoryEPSS 0.5%CVE-2026-32761MEDIUMFile Browser has an Authorization Policy Bypass in its Public Share Download FlowEPSS 0.5%CVE-2026-54097HIGHFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefixEPSS 0.4%CVE-2026-35605MEDIUMFile Browser has an access rule bypass via HasPrefix without trailing separator in path matchingEPSS 0.4%CVE-2026-32758MEDIUMFile Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination ParameterEPSS 0.4%CVE-2026-54090HIGHFile Browser: Command Allowlist Bypass via Shell Metacharacter InjectionEPSS 0.4%CVE-2026-90928HIGHFile Browser through 2.63.23 Memory Exhaustion via subtitle endpointEPSS 0.4%CVE-2026-90929HIGHFile Browser 2.5.0 Directory Deletion via Upload Failure CleanupEPSS 0.4%CVE-2026-90927HIGHfilebrowser through 2.63.23 Denial of Service via unbounded WebSocket messageEPSS 0.4%CVE-2026-73611HIGHFile Browser 2.50.0 through 2.63.21 JWT Expiration BypassEPSS 0.4%