Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Cloudreve — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting Cloudreve. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page presents vulnerability data for Cloudreve, a cloud storage system software, categorized under web application weaknesses. It aggregates security advisories and issue reports collected from the vendor and various public databases, covering vulnerabilities identified between 2021 and 2024. By accessing this resource, security professionals and system administrators can track a vendor's security response patterns, gain deeper insights into specific weakness classes affecting the platform, and review a product’s historical vulnerability trends to inform risk management and patching strategies. The content focuses on structural insights rather than immediate emergency notifications, offering a consolidated view of how issues are disclosed and resolved over time. This approach helps users identify recurring attack vectors, such as authentication flaws, file upload vulnerabilities, or information disclosure incidents, which are common in self-hosted storage solutions. The aggregation includes severity ratings, affected versions, and patch availability where applicable, enabling teams to prioritize remediation efforts based on historical data and exposure levels. It serves as a reference for understanding the security posture of Cloudreve installations and supports long-term infrastructure planning by highlighting systemic risks associated with the software ecosystem. The data is curated to provide context rather than raw feed streams, allowing for meaningful analysis of vulnerability management effectiveness. This summary aims to assist in building a comprehensive risk profile for environments relying on this specific storage solution, facilitating more informed decision-making regarding deployment, configuration, and ongoing maintenance practices without promoting any specific vendor or product.

Top products by Cloudreve: Cloudreve
CVE IDTitleCVSSSeverityPublished
CVE-2026-62323 Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored — cloudreveCWE-863 6.3 Medium2026-07-31
CVE-2026-55502 Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials — cloudreveCWE-863 7.1 High2026-07-31
CVE-2026-55499 Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients — cloudreveCWE-863 4.3 Medium2026-07-31
CVE-2026-55497 Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS) — cloudreveCWE-400 6.5 Medium2026-07-31
CVE-2026-55496 Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate — cloudreveCWE-200 4.3 Medium2026-07-31
CVE-2026-55495 Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account — cloudreveCWE-22 4.3 Medium2026-07-31
CVE-2026-54560 Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim — cloudreveCWE-863 7.6 High2026-07-15
CVE-2026-54563 Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its configured account root — cloudreveCWE-863 7.1 High2026-07-15
CVE-2026-54562 Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses — cloudreveCWE-918 6.5 Medium2026-07-15
CVE-2026-25726 Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) — cloudreveCWE-338 8.1 High2026-04-03
CVE-2022-32167 Cloudreve - Stored XSS — CloudreveCWE-79 5.4 Medium2022-09-20

This page lists every published CVE security advisory associated with Cloudreve. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.