Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

filebrowser — Vulnerabilities & Security Advisories 69

All 69 CVE vulnerabilities found in filebrowser, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specifically affecting the FileBrowser product, focusing on its specific weakness types and associated tags. It collects a comprehensive history of security advisories and defect reports, covering the full timeline of identified flaws in the software. Users can track the vendor’s security posture over time, understand common weakness classes within the codebase, and review the complete vulnerability history for FileBrowser to assess risk exposure without needing to search individual databases manually.

Vendor: filebrowser

CVE ID Title CVSS Severity Published
CVE-2026-90930 File Browser through 2.63.23 Path Traversal via Symlink Alias CWE-59 6.8 Medium 2026-09-14
CVE-2026-90928 File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint CWE-400 6.5 Medium 2026-09-14
CVE-2026-90929 File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup CWE-863 8.1 High 2026-09-14
CVE-2026-90927 filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message CWE-400 6.5 Medium 2026-09-14
CVE-2026-82237 filebrowser through 2.63.23 Stale Share Link via File Rename CWE-459 3.1 Low 2026-08-28
CVE-2026-82238 filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads CWE-367 3.1 Low 2026-08-28
CVE-2026-82236 File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion CWE-459 3.1 Low 2026-08-28
CVE-2026-82235 filebrowser through 2.63.23 Denial of Service via named pipes CWE-400 5.9 Medium 2026-08-28
CVE-2026-62684 File Browser: Share API exposes the password hash and bypass token CWE-200 2.7 Low 2026-08-18
CVE-2026-72838 FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload CWE-770 6.5 Medium 2026-08-14
CVE-2026-72837 File Browser before 2.63.20 Privilege Escalation via Proxy Authentication CWE-284 8.8 High 2026-08-14
CVE-2026-72835 filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization CWE-41 6.8 Medium 2026-08-14
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass CWE-178 8.1 High 2026-08-14
CVE-2026-72834 filebrowser before 2.63.19 Permission Bypass via checksum CWE-200 4.3 Medium 2026-08-14
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup CWE-266 9.8 Critical 2026-08-13
CVE-2026-73613 filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink CWE-59 8.2 High 2026-08-13
CVE-2026-73612 File Browser before v2.63.22 Authorization Bypass via Recursive Operations CWE-639 8.1 High 2026-08-13
CVE-2026-73611 File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass CWE-613 6.8 Medium 2026-08-13
CVE-2026-54910 FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files CWE-22 7.7 High 2026-07-20
CVE-2026-54685 FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel CWE-208 5.3 Medium 2026-07-20
CVE-2026-46410 FileBrowser Quantum: unauthenticated user share share info CWE-200 - - 2026-07-20
CVE-2026-62685 File Browser: Colliding username normalization gives two users the same home directory CWE-647 8.1 High 2026-07-15
CVE-2026-62843 File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) CWE-22 6.8 Medium 2026-07-15
CVE-2026-62683 File Browser: Trailing-slash delete leaves a stale public share behind CWE-863 3.1 Low 2026-07-15
CVE-2026-61874 filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete CWE-863 3.1 Low 2026-07-12
CVE-2026-55668 File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope CWE-22 6.3 Medium 2026-07-08
CVE-2026-54090 File Browser: Command Allowlist Bypass via Shell Metacharacter Injection CWE-77 - - 2026-06-25
CVE-2026-54088 File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) CWE-78 - - 2026-06-25
CVE-2026-54089 File Browser: Authentication Bypass via Proxy Auth Header Forgery CWE-287 9.1 Critical 2026-06-25
CVE-2026-54091 File Browser: Incorrect access control in public directory shares via rule path rebasing CWE-863 7.5 High 2026-06-25

All 69 known CVE vulnerabilities affecting filebrowser with full Chinese analysis, references, and POCs where available.