Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

FileRise — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in FileRise, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the vendor FileRise, specifically focusing on software weaknesses and their corresponding tags. It collects a comprehensive set of reported flaws affecting FileRise products, covering the full historical range from initial public disclosures to recent updates. Readers can use this resource to track vendor advisories, understand specific weakness classes within the FileRise ecosystem, and review the complete vulnerability history for any given product. The data is organized to facilitate technical analysis rather than general awareness, allowing security professionals and developers to identify patterns in reported issues. By consolidating information from multiple sources into a single view, this aggregation helps clarify the security posture of FileRise software over time. Users can filter entries by severity, weakness type, or affected component to isolate relevant threats for their specific environment. This structured approach supports risk assessment and patch management strategies by providing a clear timeline of known issues. The collection includes both critical and lower-severity findings, ensuring that even minor defects are documented for long-term trend analysis. No specific CVE identifiers are listed in this introductory summary, but the underlying database contains detailed references for each entry. This page serves as a technical reference point for those monitoring the security landscape of FileRise, offering insights into how vulnerabilities have evolved and been addressed by the vendor. It is designed for direct consumption by security teams who need to verify exposure or plan remediation efforts based on historical data.

Vendor: error311

CVE ID Title CVSS Severity Published
CVE-2026-92616 FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance CWE-613 6.8 Medium 2026-09-16
CVE-2026-54414 FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover CWE-22 9.8 Critical 2026-06-19
CVE-2026-44460 FileRise: TOTP Bypass via Setup Endpoint Disclosing Existing Secret CWE-200 7.4 High 2026-05-27
CVE-2026-33477 FileRise has incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file content CWE-863 4.3 Medium 2026-03-26
CVE-2026-33330 FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback CWE-863 7.1 High 2026-03-24
CVE-2026-33329 FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle CWE-22 8.1 High 2026-03-24
CVE-2026-33072 FileRise: Default Encryption Key Enables Token Forgery and Config Decryption CWE-798 8.2 High 2026-03-20
CVE-2026-33071 FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads CWE-434 4.3 Medium 2026-03-20
CVE-2026-33070 FileRise has Unauthenticated Share Link Deletion CWE-306 3.7 Low 2026-03-20
CVE-2026-25231 FileRise affected by an Unauthenticated File Read Due to Insufficient Access Control CWE-284 7.5 High 2026-02-09
CVE-2026-25230 FileRise affected by HTML Injection using color property in file tags CWE-79 4.6 Medium 2026-02-09
CVE-2025-68116 FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling CWE-79 8.9 High 2025-12-16
CVE-2025-66403 FileRise Vulnerable to Stored XSS via SVG Upload CWE-79 4.6 Medium 2025-12-01
CVE-2025-62510 FileRise insecure folder visibility via name-based mapping and incomplete ACL checks CWE-280 8.1 High 2025-10-20
CVE-2025-62509 FileRise improper ownership/permission validation allowed cross-tenant file operations CWE-280 8.1 High 2025-10-20

All 15 known CVE vulnerabilities affecting FileRise with full Chinese analysis, references, and POCs where available.