CVE-2026-54097
- EPSS 0.41%
- Veröffentlicht 25.06.2026 17:40:18
- Zuletzt bearbeitet 26.06.2026 14:17:05
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, a low-privileged authenticated user of filebrowser (with create + delete permissions in their ow...
CVE-2026-54093
- EPSS 0.19%
- Veröffentlicht 25.06.2026 17:39:06
- Zuletzt bearbeitet 25.06.2026 19:58:30
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, filebrowser builds the download-as-zip / download-as-tar archive entry names with filepath.ToSla...
CVE-2026-54094
- EPSS 0.47%
- Veröffentlicht 25.06.2026 17:37:14
- Zuletzt bearbeitet 25.06.2026 19:58:30
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTTP file handlers from following symbolic links before they open, serve, ...
CVE-2026-54096
- EPSS 0.18%
- Veröffentlicht 25.06.2026 17:35:02
- Zuletzt bearbeitet 25.06.2026 19:58:30
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and stores a pub...
CVE-2026-55667
- EPSS 0.44%
- Veröffentlicht 25.06.2026 17:32:32
- Zuletzt bearbeitet 26.06.2026 04:17:46
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary f...
CVE-2026-35607
- EPSS 0.38%
- Veröffentlicht 07.04.2026 16:31:21
- Zuletzt bearbeitet 16.04.2026 18:14:56
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute per...
CVE-2026-35606
- EPSS 0.27%
- Veröffentlicht 07.04.2026 16:29:03
- Zuletzt bearbeitet 16.04.2026 18:16:28
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the P...
CVE-2026-35605
- EPSS 0.39%
- Veröffentlicht 07.04.2026 16:24:52
- Zuletzt bearbeitet 16.04.2026 18:23:47
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the Matches() function in rules/rules.go uses strings.HasPrefix() without a trailing directory s...
CVE-2026-35604
- EPSS 0.33%
- Veröffentlicht 07.04.2026 16:22:51
- Zuletzt bearbeitet 16.04.2026 18:30:57
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by t...
CVE-2026-35585
- EPSS 1.92%
- Veröffentlicht 07.04.2026 16:20:46
- Zuletzt bearbeitet 09.06.2026 13:16:35
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 until 2.33.8, the hook system in File Browser — which executes administrator-defined shell commands on...