CVE-2026-25231
- EPSS 0.08%
- Veröffentlicht 09.02.2026 18:34:36
- Zuletzt bearbeitet 19.02.2026 19:31:59
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can...
CVE-2026-25230
- EPSS 0.04%
- Veröffentlicht 09.02.2026 18:32:09
- Zuletzt bearbeitet 19.02.2026 20:02:58
FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user ...
CVE-2025-68116
- EPSS 0.05%
- Veröffentlicht 16.12.2025 16:43:30
- Zuletzt bearbeitet 02.01.2026 16:48:47
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. ...
CVE-2025-66403
- EPSS 0.04%
- Veröffentlicht 01.12.2025 22:20:56
- Zuletzt bearbeitet 07.01.2026 20:50:05
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in the Filerise application due to improper handling of uploaded SVG file...
CVE-2025-62510
- EPSS 0.05%
- Veröffentlicht 20.10.2025 17:39:10
- Zuletzt bearbeitet 04.12.2025 19:12:57
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inferred from folder names. Low-privilege users could see or interact wit...
CVE-2025-62509
- EPSS 0.05%
- Veröffentlicht 20.10.2025 17:38:49
- Zuletzt bearbeitet 04.12.2025 19:13:01
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (vi...