Home/Product/filebrowser
Product

filebrowser

35 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-35607
<= 2.63.0
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
8.1HIGH
CVE-2026-35606
<= 2.63.0
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
7.5HIGH
CVE-2026-35605
< 2.63.1
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
7.5HIGH
CVE-2026-35604
< 2.63.1
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
8.1HIGH
CVE-2026-35585
>= 2.0.0 and <= 2.63.1
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
7.2HIGH
CVE-2026-34530
< 2.62.2
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
6.9MEDIUM
CVE-2026-34529
< 2.62.2
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
7.6HIGH
CVE-2026-34528
< 2.62.2
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
8.1HIGH
CVE-2026-32761
< 2.62.0
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
6.5MEDIUM
CVE-2026-32760
< 2.62.0
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
9.8CRITICAL
CVE-2026-32759
<= 2.61.2
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
8.1HIGH
CVE-2026-32758
< 2.62.0
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified dire
6.5MEDIUM
CVE-2026-30934
<= 1.2.9
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible v
8.9HIGH
CVE-2026-30933
<= 1.2.9
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-
7.5HIGH
CVE-2026-29188
< 2.61.1
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
9.1CRITICAL
CVE-2026-28492
>= 2.0.0 and < 2.61.0
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
6.5MEDIUM
CVE-2026-25890
< 2.57.1
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
8.1HIGH
CVE-2026-25889
< 2.57.1
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
5.4MEDIUM
CVE-2026-23849
< 2.55.0
File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, a
5.3MEDIUM
CVE-2025-64523
< 2.45.1
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
8.8HIGH
CVE-2025-53893
all versions
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
6.5MEDIUM
CVE-2025-53826
all versions
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
9.8CRITICAL
CVE-2025-52997
< 2.34.1
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
5.9MEDIUM
CVE-2025-52996
<= 2.32.0
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
3.1LOW
CVE-2025-52995
<= 2.33.8
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
8.0HIGH
CVE-2025-52901
<= 2.33.0
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
4.5MEDIUM
CVE-2025-52904
all versions
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
8.0HIGH
CVE-2025-52903
all versions
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
8.0HIGH
CVE-2025-52902
< 2.33.7
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
7.6HIGH
CVE-2025-52900
< 2.33.7
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename
5.5MEDIUM
CVE-2023-39612
< 2.25.0
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges t
9.0CRITICAL
CVE-2021-46398
< 2.18.0
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with adm
8.8HIGH
CVE-2021-37794
< 2.16.0
A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to
5.4MEDIUM
CVE-2013-2036
all versions
Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to in
CVE-2007-4921
all versions
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execu
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin