📦 Filebrowser

by Filebrowser

🔍 What is Filebrowser?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53826

CRITICAL CVSS 9.8 Jul 15, 2025

File Browser version 2.39.0 has an authentication flaw where JWT tokens remain valid indefinitely even after user logout. This allows attackers with stolen tokens to maintain unauthorized access to fi...

CVE-2023-39612

CRITICAL CVSS 9.0 Sep 16, 2023

This cross-site scripting (XSS) vulnerability in FileBrowser allows authenticated attackers to escalate privileges to Administrator by tricking users into interacting with malicious HTML files or URLs...

CVE-2026-25890

HIGH CVSS 8.1 Feb 9, 2026

In File Browser versions before 2.57.1, authenticated users can bypass file access restrictions by adding extra slashes to file paths in requests. This allows unauthorized access to files that should ...

CVE-2025-64523

HIGH CVSS 8.8 Nov 12, 2025

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in File Browser versions before 2.45.1. Any authenticated user with share permissions can delete other users' shared links w...

CVE-2025-52995

HIGH CVSS 8.0 Jun 30, 2025

CVE-2025-52995 is an improper command allowlist vulnerability in File Browser that allows authenticated users to execute unauthorized shell commands. This could lead to arbitrary command execution, fi...

CVE-2025-52903

HIGH CVSS 8.0 Jun 26, 2025

CVE-2025-52903 is a command injection vulnerability in File Browser version 2.32.0 that allows authenticated users with 'Execute commands' permission to bypass allowlist restrictions and execute arbit...

CVE-2025-52902

HIGH CVSS 7.6 Jun 26, 2025

File Browser versions prior to 2.33.7 have a stored cross-site scripting (XSS) vulnerability in the Markdown preview function. When users upload Markdown files containing JavaScript code, that code ex...

CVE-2026-25889

MEDIUM CVSS 5.4 Feb 9, 2026

A case-sensitivity flaw in File Browser's password validation allows authenticated users to change passwords without providing the current password. By using 'Password' instead of 'password' in API re...

CVE-2026-23849

MEDIUM CVSS 5.3 Jan 19, 2026

This CVE describes a timing attack vulnerability in File Browser's authentication mechanism that allows unauthenticated attackers to enumerate valid usernames by measuring response time differences. T...

CVE-2025-52997

MEDIUM CVSS 5.9 Jun 30, 2025

File Browser versions before 2.34.1 lack password policy enforcement and brute-force protection, allowing attackers to guess passwords through repeated authentication attempts. This affects all File B...