Browse all 10 CVE security advisories affecting Rejetto. AI-powered Chinese analysis, POCs, and references for each vulnerability.
This page aggregates known security weaknesses associated with the vendor Rejetto, focusing specifically on issues related to their HFS HTTP File Server product line. It covers a comprehensive collection of vulnerability data, including common vulnerabilities and exposures (CVEs), spanning from the earliest discovered flaws up to the present date to provide a complete historical perspective on the software's security posture. Visitors to this resource can effectively track Rejetto’s official security advisories and public response patterns, gain a deeper understanding of recurring weakness classes such as remote code execution or path traversal vulnerabilities within this specific ecosystem, and conduct detailed lookups into a product's vulnerability history to assess long-term maintenance trends and risk profiles over time. By centralizing these disparate data points, the page aims to simplify the process of researching the security landscape surrounding Rejetto’s software offerings. Users can identify patterns in how vulnerabilities were reported, patched, or left unresolved, which is critical for administrators relying on this toolset. The information presented here is derived from publicly available security databases and vendor announcements, ensuring that the records are accessible for audit, compliance, and risk assessment purposes without requiring proprietary subscriptions. This aggregation serves as a neutral reference point for security analysts and IT professionals seeking factual historical data on Rejetto-related security incidents.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-61505 | Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter — hfs CWE-22 | 5.3 | Medium | 2026-07-13 |
| CVE-2026-61504 | Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing — hfs CWE-79 | 5.4 | Medium | 2026-07-13 |
| CVE-2026-61503 | Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences — hfs CWE-204 | 5.3 | Medium | 2026-07-13 |
| CVE-2026-61502 | Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests — hfs CWE-352 | 4.3 | Medium | 2026-07-13 |
| CVE-2026-61501 | Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer — hfs CWE-79 | 6.1 | Medium | 2026-07-13 |
| CVE-2026-61500 | Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key — hfs CWE-338 | 9.8 | Critical | 2026-07-13 |
This page lists every published CVE security advisory associated with Rejetto. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.