filebrowser
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting filebrowser.
- CVE-2026-72837File Browser before 2.63.20 Privilege Escalation via Proxy Authentication8.8
- CVE-2026-72838FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload6.5
- CVE-2026-72836FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass8.1
- CVE-2026-72835filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization6.8
- CVE-2026-72834filebrowser before 2.63.19 Permission Bypass via checksum4.3
- CVE-2026-72839filebrowser through 2.63.16 Privilege Escalation via Signup9.8
- CVE-2026-73613filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink8.2
- CVE-2026-73611File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass6.8
- CVE-2026-73612File Browser before v2.63.22 Authorization Bypass via Recursive Operations8.1
- CVE-2026-62685File Browser: Colliding username normalization gives two users the same home directory8.1
- CVE-2026-62843File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)6.8
- CVE-2026-62683File Browser: Trailing-slash delete leaves a stale public share behind3.1
- CVE-2026-61874filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete3.1
- CVE-2026-55668File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope6.3
- CVE-2026-54089File Browser: Authentication Bypass via Proxy Auth Header Forgery9.1