CVEs we hold for Filebrowser
Records whose assigning authority named Filebrowser as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-90927filebrowser through 2.63.23 Denial of Service via unbounded WebSocket messagefilebrowser
CVE-2026-62843File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)filebrowser
CVE-2026-62685File Browser: Colliding username normalization gives two users the same home directoryfilebrowser
CVE-2026-55668File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scopefilebrowser
CVE-2026-55667File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload…filebrowser
CVE-2026-54097File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefixfilebrowser
CVE-2026-54096File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Pathfilebrowser
CVE-2026-54094File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scopefilebrowser
CVE-2026-54093File Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators in stored filenamesfilebrowser
CVE-2026-54091File Browser: Incorrect access control in public directory shares via rule path rebasingfilebrowser
CVE-2026-54088File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)filebrowser
CVE-2026-35607File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commandsfilebrowser
CVE-2026-35606File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download checkfilebrowser
CVE-2026-35605File Browser has an access rule bypass via HasPrefix without trailing separator in path matchingfilebrowser
CVE-2026-35604File Browser share links remain accessible after Share/Download permissions are revokedfilebrowser
CVE-2026-34530File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injectionfilebrowser
CVE-2026-34529File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB filefilebrowser
CVE-2026-34528File Browser's Signup Grants Execution Permissions When Default Permissions Includes Executionfilebrowser
CVE-2026-32761File Browser has an Authorization Policy Bypass in its Public Share Download Flowfilebrowser
CVE-2026-32760File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Adminfilebrowser
CVE-2026-32759File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurelyfilebrowser
CVE-2026-32758File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameterfilebrowser
CVE-2026-28492File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directoryfilebrowser
CVE-2026-25890File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URLfilebrowser
CVE-2026-23849File Browser vulnerable to Username Enumeration via Timing Attack in /api/loginfilebrowser
CVE-2025-64523FileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Functionfilebrowser
CVE-2025-53893File Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processingfilebrowser
CVE-2025-53826FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logoutfilebrowser
CVE-2025-52903File Browser Allows Execution of Shell Commands That Can Spawn Other Commandsfilebrowser
61 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.