Keking
Keking Kkfileview: vulnerabilidades y CVE
Keking Kkfileview tiene 16 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88592 | Crítica (9.1) | 0.21% | — | 16 sept 2026 | kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter… |
| CVE-2026-88593 | Media (6.1) | 0.25% | — | 16 sept 2026 | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without… |
| CVE-2026-73244 | Media (5.3) | 0.44% | — | 11 ago 2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the… |
| CVE-2026-73243 | Media (5.8) | 0.43% | — | 11 ago 2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in… |
| CVE-2025-4538 | Media (5.3) | 0.40% | — | 11 may 2025 | A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. It is possible… |
| CVE-2023-48815 | Media (6.1) | 0.46% | — | 4 dic 2023 | kkFileView v4.3.0 is vulnerable to Incorrect Access Control. |
| CVE-2022-46934 | Media (6.1) | 1.1% | — | 1 feb 2023 | kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java. |
| CVE-2022-4740 | Media (6.1) | 0.55% | — | 25 dic 2022 | A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWatermarkAttribute of the file /picturesPreview. The manipulation leads to cross site… |
| CVE-2022-43140 | Alta (7.5) | 2.0% | — | 17 nov 2022 | kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the… |
| CVE-2022-42147 | Media (6.1) | 0.44% | — | 17 oct 2022 | kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java. |
| CVE-2022-42149 | Crítica (9.8) | 2.4% | — | 17 oct 2022 | kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java. |
| CVE-2022-40879 | Media (6.1) | 1.3% | — | 29 sept 2022 | kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.' |
| CVE-2022-36593 | Media (6.5) | 0.91% | — | 2 sept 2022 | kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java. |
| CVE-2022-35151 | Media (6.1) | 1.4% | — | 17 ago 2022 | kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java. |
| CVE-2022-29349 | Media (6.1) | 1.8% | — | 25 may 2022 | kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java. |
| CVE-2021-43734 | Alta (7.5) | 11% | — | 15 feb 2022 | kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host. |