Filebrowser
Filebrowser File Browser: vulnerabilidades y CVE
Filebrowser File Browser tiene 18 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses18
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90930 | Alta (7.6) | 0.50% | — | 14 sept 2026 | File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and… |
| CVE-2026-90929 | Alta (7.2) | 0.44% | — | 14 sept 2026 | File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler… |
| CVE-2026-90928 | Alta (7.1) | 0.44% | — | 14 sept 2026 | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download… |
| CVE-2026-82236 | Baja (2.3) | 0.35% | — | 28 ago 2026 | File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated… |
| CVE-2026-62684 | Baja (2.7) | 0.43% | — | 18 ago 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by… |
| CVE-2026-73612 | Alta (8.6) | 0.48% | — | 13 ago 2026 | File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy,… |
| CVE-2026-73611 | Alta (7.6) | 0.43% | — | 13 ago 2026 | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected… |
| CVE-2026-62843 | Media (6.8) | 0.39% | — | 15 jul 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses… |
| CVE-2026-62685 | Alta (8.1) | 0.55% | — | 15 jul 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed… |
| CVE-2026-62683 | Baja (3.1) | 0.32% | — | 15 jul 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the… |
| CVE-2026-55668 | Media (6.3) | 0.38% | — | 8 jul 2026 | File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an… |
| CVE-2026-55667 | Alta (8.2) | 0.49% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create… |
| CVE-2026-54096 | Alta (8.4) | 0.18% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an… |
| CVE-2026-54094 | Alta (7.5) | 0.50% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTTP file handlers from following symbolic… |
| CVE-2026-54092 | Media (6.5) | 0.55% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large… |
| CVE-2026-54091 | Alta (7.5) | 0.52% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase the share owner's… |
| CVE-2026-54090 | Alta (8.7) | 0.44% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.33.8, when a shell interpreter is configured (e.g. /bin/sh -c), the… |
| CVE-2026-54088 | Crítica (9.3) | 0.76% | — | 25 jun 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.