filebrowser
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting filebrowser.
- CVE-2026-62685File Browser: Colliding username normalization gives two users the same home directory8.1
- CVE-2026-62843File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)6.8
- CVE-2026-62683File Browser: Trailing-slash delete leaves a stale public share behind3.1
- CVE-2026-61874filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete3.1
- CVE-2026-55668File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope6.3
- CVE-2026-54089File Browser: Authentication Bypass via Proxy Auth Header Forgery9.1
- CVE-2026-54091File Browser: Incorrect access control in public directory shares via rule path rebasing7.5
- CVE-2026-54092File Browser: DoS Vulnerability on Public Login API6.5
- CVE-2026-54094File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope7.5
- CVE-2026-54096File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path8.4
- CVE-2026-55667File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup8.2
- CVE-2026-35607File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands8.1
- CVE-2026-35606File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check7.5
- CVE-2026-35605File Browser has an access rule bypass via HasPrefix without trailing separator in path matching7.5
- CVE-2026-35604File Browser share links remain accessible after Share/Download permissions are revoked8.1