- EPSS 0.32%
- Veröffentlicht 01.04.2026 20:39:07
- Zuletzt bearbeitet 06.04.2026 20:39:47
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (...
CVE-2026-32761
- EPSS 0.42%
- Veröffentlicht 19.03.2026 23:45:33
- Zuletzt bearbeitet 23.03.2026 16:56:04
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download priv...
CVE-2026-32760
- EPSS 0.67%
- Veröffentlicht 19.03.2026 23:39:54
- Zuletzt bearbeitet 23.03.2026 16:54:48
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-reg...
CVE-2026-32759
- EPSS 1.9%
- Veröffentlicht 19.03.2026 23:31:51
- Zuletzt bearbeitet 09.06.2026 13:16:35
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33.8, the TUS resumable upload handler parses the Upload-Length header a...
CVE-2026-32758
- EPSS 0.39%
- Veröffentlicht 19.03.2026 23:22:19
- Zuletzt bearbeitet 23.03.2026 16:55:20
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). T...
CVE-2026-30934
- EPSS 0.35%
- Veröffentlicht 10.03.2026 16:12:23
- Zuletzt bearbeitet 18.03.2026 16:52:51
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context...
CVE-2026-30933
- EPSS 0.54%
- Veröffentlicht 10.03.2026 16:10:56
- Zuletzt bearbeitet 18.03.2026 17:13:34
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. Thi...
CVE-2026-28492
- EPSS 0.32%
- Veröffentlicht 05.03.2026 21:06:21
- Zuletzt bearbeitet 10.03.2026 19:34:55
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile midd...
CVE-2026-29188
- EPSS 0.49%
- Veröffentlicht 05.03.2026 20:57:57
- Zuletzt bearbeitet 10.03.2026 19:42:36
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allo...
CVE-2026-25890
- EPSS 0.46%
- Veröffentlicht 09.02.2026 21:21:50
- Zuletzt bearbeitet 20.02.2026 20:31:02
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modif...