CVE-2026-34530
- EPSS 0.36%
- Veröffentlicht 01.04.2026 20:41:08
- Zuletzt bearbeitet 06.04.2026 20:34:21
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the SPA index page in File Browser is vulnerable to Stored Cross-Site Scripting (XSS) vi...
CVE-2026-34528
- EPSS 0.65%
- Veröffentlicht 01.04.2026 20:39:32
- Zuletzt bearbeitet 06.04.2026 20:41:19
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler in File Browser applies default user permissions via d.settings.Defaul...
- EPSS 0.32%
- Veröffentlicht 01.04.2026 20:39:07
- Zuletzt bearbeitet 06.04.2026 20:39:47
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (...
CVE-2026-32761
- EPSS 0.42%
- Veröffentlicht 19.03.2026 23:45:33
- Zuletzt bearbeitet 23.03.2026 16:56:04
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download priv...
CVE-2026-32760
- EPSS 0.67%
- Veröffentlicht 19.03.2026 23:39:54
- Zuletzt bearbeitet 23.03.2026 16:54:48
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-reg...
CVE-2026-32759
- EPSS 1.9%
- Veröffentlicht 19.03.2026 23:31:51
- Zuletzt bearbeitet 09.06.2026 13:16:35
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33.8, the TUS resumable upload handler parses the Upload-Length header a...
CVE-2026-32758
- EPSS 0.39%
- Veröffentlicht 19.03.2026 23:22:19
- Zuletzt bearbeitet 23.03.2026 16:55:20
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). T...
CVE-2026-30934
- EPSS 0.35%
- Veröffentlicht 10.03.2026 16:12:23
- Zuletzt bearbeitet 18.03.2026 16:52:51
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context...
CVE-2026-30933
- EPSS 0.54%
- Veröffentlicht 10.03.2026 16:10:56
- Zuletzt bearbeitet 18.03.2026 17:13:34
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. Thi...
CVE-2026-28492
- EPSS 0.32%
- Veröffentlicht 05.03.2026 21:06:21
- Zuletzt bearbeitet 10.03.2026 19:34:55
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile midd...