| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-33477 | FileRise has incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file content | error311 | FileRise | Medium | 4.3 | 2026-03-26 17:09:00 | Deep Dive |
| CVE-2026-33330 | FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback | error311 | FileRise | High | 7.1 | 2026-03-24 19:15:03 | Deep Dive |
| CVE-2026-33329 | FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle | error311 | FileRise | High | 8.1 | 2026-03-24 19:14:43 | Deep Dive |
| CVE-2026-33072 | FileRise: Default Encryption Key Enables Token Forgery and Config Decryption | error311 | FileRise | High | 8.2 | 2026-03-20 08:31:08 | Deep Dive |
| CVE-2026-33071 | FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads | error311 | FileRise | Medium | 4.3 | 2026-03-20 08:27:37 | Deep Dive |
| CVE-2026-33070 | FileRise has Unauthenticated Share Link Deletion | error311 | FileRise | Low | 3.7 | 2026-03-20 08:25:07 | Deep Dive |
| CVE-2026-25231 | FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control | error311 | FileRise | High | 7.5 | 2026-02-09 18:34:37 | Deep Dive |
| CVE-2026-25230 | FileRise affected by HTML Injection using color property in file tags | error311 | FileRise | Medium | 4.6 | 2026-02-09 18:32:10 | Deep Dive |
| CVE-2025-68116 | FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling | error311 | FileRise | High | 8.9 | 2025-12-16 16:43:30 | Deep Dive |
| CVE-2025-66403 | FileRise Vulnerable to Stored XSS via SVG Upload | error311 | FileRise | Medium | 4.6 | 2025-12-01 22:20:57 | Deep Dive |
| CVE-2025-62510 | FileRise insecure folder visibility via name-based mapping and incomplete ACL checks | error311 | FileRise | High | 8.1 | 2025-10-20 17:39:10 | Deep Dive |
| CVE-2025-62509 | FileRise improper ownership/permission validation allowed cross-tenant file operations | error311 | FileRise | High | 8.1 | 2025-10-20 17:38:50 | Deep Dive |