CVE-2026-33477
- EPSS 0.03%
- Veröffentlicht 26.03.2026 17:09:00
- Zuletzt bearbeitet 31.03.2026 12:38:12
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.7 through 3.10.0, the file snippet endpoint `/api/file/snippet.php` allows an authenticated user with only `read_own` access to a ...
CVE-2026-33330
- EPSS 0.01%
- Veröffentlicht 24.03.2026 19:15:03
- Zuletzt bearbeitet 26.03.2026 11:58:39
FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file ...
CVE-2026-33329
- EPSS 0.08%
- Veröffentlicht 24.03.2026 19:14:42
- Zuletzt bearbeitet 26.03.2026 11:59:50
FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handler (UploadModel::handleUpload()) is concatenated directly into filesyst...
CVE-2026-33072
- EPSS 0.01%
- Veröffentlicht 20.03.2026 08:31:08
- Zuletzt bearbeitet 23.03.2026 15:53:41
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_this_key) is used for all cryptographic operations — HMAC token generation, AES config encryption, and s...
CVE-2026-33071
- EPSS 0.17%
- Veröffentlicht 20.03.2026 08:27:37
- Zuletzt bearbeitet 23.03.2026 15:36:46
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml, .php5, .htaccess, and other server-side executable types, bypassing the filename validatio...
CVE-2026-33070
- EPSS 0.04%
- Veröffentlicht 20.03.2026 08:25:07
- Zuletzt bearbeitet 23.03.2026 15:33:39
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnerability in the deleteShareLink endpoint allows any unauthenticated user to delete arbitrary file share links by providing only the ...
CVE-2026-25231
- EPSS 0.11%
- Veröffentlicht 09.02.2026 18:34:36
- Zuletzt bearbeitet 19.02.2026 19:31:59
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can...
CVE-2026-25230
- EPSS 0.05%
- Veröffentlicht 09.02.2026 18:32:09
- Zuletzt bearbeitet 19.02.2026 20:02:58
FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user ...
CVE-2025-68116
- EPSS 0.05%
- Veröffentlicht 16.12.2025 16:43:30
- Zuletzt bearbeitet 02.01.2026 16:48:47
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. ...
CVE-2025-66403
- EPSS 0.05%
- Veröffentlicht 01.12.2025 22:20:56
- Zuletzt bearbeitet 07.01.2026 20:50:05
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG file...