CVE-2026-62685
- EPSS 0.32%
- Veröffentlicht 15.07.2026 15:47:23
- Zuletzt bearbeitet 20.07.2026 16:17:06
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=t...
CVE-2026-62843
- EPSS 0.26%
- Veröffentlicht 15.07.2026 15:42:19
- Zuletzt bearbeitet 15.07.2026 18:15:13
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which tu...
CVE-2026-62683
- EPSS 0.2%
- Veröffentlicht 15.07.2026 15:40:56
- Zuletzt bearbeitet 15.07.2026 19:18:38
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the shared directory is deleted thr...
CVE-2026-61874
- EPSS 0.2%
- Veröffentlicht 12.07.2026 12:16:46
- Zuletzt bearbeitet 13.07.2026 20:03:31
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path...
CVE-2026-55668
- EPSS 0.27%
- Veröffentlicht 08.07.2026 14:55:25
- Zuletzt bearbeitet 08.07.2026 17:17:24
File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create an...
CVE-2026-54090
- EPSS 0.32%
- Veröffentlicht 25.06.2026 17:51:17
- Zuletzt bearbeitet 26.06.2026 16:16:32
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.33.8, when a shell interpreter is configured (e.g. /bin/sh -c), the command allowlist can be bypassed ...
CVE-2026-54088
- EPSS 0.63%
- Veröffentlicht 25.06.2026 17:49:14
- Zuletzt bearbeitet 25.06.2026 19:58:30
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verifica...
CVE-2026-54089
- EPSS 0.43%
- Veröffentlicht 25.06.2026 17:46:13
- Zuletzt bearbeitet 25.06.2026 19:58:30
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unaut...
CVE-2026-54091
- EPSS 0.47%
- Veröffentlicht 25.06.2026 17:43:04
- Zuletzt bearbeitet 26.06.2026 19:16:42
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase the share owner's filesystem root to the shared dire...
CVE-2026-54092
- EPSS 0.48%
- Veröffentlicht 25.06.2026 17:41:43
- Zuletzt bearbeitet 26.06.2026 04:17:46
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login...