Vulnerabilities in filebrowser

43 results
Vexday analysis

O filebrowser apresenta um volume significativo de vulnerabilidades (43 CVEs) com concentração recente: 15 publicadas nos últimos 90 dias. Embora nenhuma esteja sob exploração ativa conhecida, 4 vulnerabilidades críticas foram registradas, sendo a falha de controle de acesso (CWE-863) o padrão dominante. O risco é moderado e em evolução, exigindo monitoramento atento das correções disponibilizadas.

CVE-2026-35585HIGHFile Browser has a Command Injection via Hook RunnerEPSS 1.9%CVE-2026-32759MEDIUMFile Browser TUS Negative Upload-Length Fires Post-Upload Hooks PrematurelyEPSS 1.9%CVE-2025-52903HIGHFile Browser Allows Execution of Shell Commands That Can Spawn Other CommandsEPSS 1.0%CVE-2025-52904HIGHFile Browser: Command Execution not Limited to ScopeEPSS 0.9%CVE-2026-32760CRITICALFile Browser Self Registration Grants Any User Admin Access When Default Permissions Include AdminEPSS 0.7%CVE-2026-34528HIGHFile Browser's Signup Grants Execution Permissions When Default Permissions Includes ExecutionEPSS 0.7%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.6%CVE-2025-52995HIGHFile Browser vulnerable to command execution allowlist bypassEPSS 0.5%CVE-2025-53826HIGHFileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after LogoutEPSS 0.5%CVE-2025-52901MEDIUMFile Browser allows sensitive data to be transferred in URLEPSS 0.5%CVE-2026-29188CRITICALFile Browser: TUS Delete Endpoint Bypasses Delete Permission CheckEPSS 0.5%CVE-2026-54092MEDIUMFile Browser: DoS Vulnerability on Public Login APIEPSS 0.5%CVE-2025-52997MEDIUMFile Browser Insecurely Handles PasswordsEPSS 0.5%CVE-2026-54091HIGHFile Browser: Incorrect access control in public directory shares via rule path rebasingEPSS 0.5%CVE-2026-54094HIGHFile Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scopeEPSS 0.5%CVE-2026-25890HIGHFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URLEPSS 0.5%CVE-2026-55667HIGHFile Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanupEPSS 0.4%CVE-2026-54089CRITICALFile Browser: Authentication Bypass via Proxy Auth Header ForgeryEPSS 0.4%CVE-2025-64523HIGHFileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion FunctionEPSS 0.4%CVE-2026-32761MEDIUMFile Browser has an Authorization Policy Bypass in its Public Share Download FlowEPSS 0.4%