« Volver al listado

Keking

Keking Kkfileview: vulnerabilidades y CVE

Keking Kkfileview tiene 16 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses4
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-88592Crítica (9.1)0.21%—16 sept 2026
kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter…
CVE-2026-88593Media (6.1)0.25%—16 sept 2026
kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without…
CVE-2026-73244Media (5.3)0.44%—11 ago 2026
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the…
CVE-2026-73243Media (5.8)0.43%—11 ago 2026
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in…
CVE-2025-4538Media (5.3)0.40%—11 may 2025
A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. It is possible…
CVE-2023-48815Media (6.1)0.46%—4 dic 2023
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
CVE-2022-46934Media (6.1)1.1%—1 feb 2023
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
CVE-2022-4740Media (6.1)0.55%—25 dic 2022
A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWatermarkAttribute of the file /picturesPreview. The manipulation leads to cross site…
CVE-2022-43140Alta (7.5)2.0%—17 nov 2022
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the…
CVE-2022-42147Media (6.1)0.44%—17 oct 2022
kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.
CVE-2022-42149Crítica (9.8)2.4%—17 oct 2022
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
CVE-2022-40879Media (6.1)1.3%—29 sept 2022
kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
CVE-2022-36593Media (6.5)0.91%—2 sept 2022
kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.
CVE-2022-35151Media (6.1)1.4%—17 ago 2022
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
CVE-2022-29349Media (6.1)1.8%—25 may 2022
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
CVE-2021-43734Alta (7.5)11%—15 feb 2022
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.