Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

filebrowser — Vulnerabilities & Security Advisories 69

All 69 CVE vulnerabilities found in filebrowser, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specifically affecting the FileBrowser product, focusing on its specific weakness types and associated tags. It collects a comprehensive history of security advisories and defect reports, covering the full timeline of identified flaws in the software. Users can track the vendor’s security posture over time, understand common weakness classes within the codebase, and review the complete vulnerability history for FileBrowser to assess risk exposure without needing to search individual databases manually.

Vendor: filebrowser

CVE ID Title CVSS Severity Published
CVE-2026-54092 File Browser: DoS Vulnerability on Public Login API CWE-1284 6.5 Medium 2026-06-25
CVE-2026-54097 File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix CWE-639 - - 2026-06-25
CVE-2026-54093 File Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames CWE-22 - - 2026-06-25
CVE-2026-54094 File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope CWE-22 7.5 High 2026-06-25
CVE-2026-54096 File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path CWE-863 8.4 High 2026-06-25
CVE-2026-55667 File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup CWE-22 8.2 High 2026-06-25
CVE-2026-48777 FileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory CWE-22 - - 2026-06-16
CVE-2026-44542 FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitrary File Deletion CWE-22 9.1 Critical 2026-05-14
CVE-2026-35607 File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands CWE-269 8.1 High 2026-04-07
CVE-2026-35606 File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check CWE-862 6.5AI Medium AI 2026-04-07
CVE-2026-35605 File Browser has an access rule bypass via HasPrefix without trailing separator in path matching CWE-22 7.3AI High AI 2026-04-07
CVE-2026-35604 File Browser share links remain accessible after Share/Download permissions are revoked CWE-863 4.3AI Medium AI 2026-04-07
CVE-2026-35585 File Browser has a Command Injection via Hook Runner CWE-78 8.8AI High AI 2026-04-07
CVE-2026-34530 File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection CWE-79 6.9 Medium 2026-04-01
CVE-2026-34528 File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution CWE-269 8.1 High 2026-04-01
CVE-2026-34529 File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file CWE-79 7.6 High 2026-04-01
CVE-2026-32761 File Browser has an Authorization Policy Bypass in its Public Share Download Flow CWE-284 6.5 Medium 2026-03-19
CVE-2026-32760 File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin CWE-269 9.8 - 2026-03-19
CVE-2026-32759 File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely CWE-190 8.1 - 2026-03-19
CVE-2026-32758 File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter CWE-863 6.5 Medium 2026-03-19
CVE-2026-30934 FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse) CWE-79 8.9 High 2026-03-10
CVE-2026-30933 FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info CWE-200 7.5 High 2026-03-10
CVE-2026-28492 File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory CWE-200 8.1 - 2026-03-05
CVE-2026-29188 File Browser: TUS Delete Endpoint Bypasses Delete Permission Check CWE-732 9.1 Critical 2026-03-05
CVE-2026-27611 FileBrowser Quantum: Password Protection Not Enforced on Shared File Links CWE-200 6.5AI Medium AI 2026-02-25
CVE-2026-25890 File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL CWE-706 8.1 High 2026-02-09
CVE-2026-25889 File Browser has an Authentication Bypass in User Password Update CWE-178 5.4 Medium 2026-02-09
CVE-2026-23849 File Browser vulnerable to Username Enumeration via Timing Attack in /api/login CWE-208 5.3 Medium 2026-01-19
CVE-2025-64523 FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function CWE-285 7.1 - 2025-11-12
CVE-2025-53826 FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout CWE-305 9.8AI Critical AI 2025-07-15

All 69 known CVE vulnerabilities affecting filebrowser with full Chinese analysis, references, and POCs where available.