Product
keking kkfileview
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-4538
CVE-2023-48815
CVE-2022-46934
CVE-2022-4740
CVE-2022-43140
CVE-2022-42147
CVE-2022-42149
CVE-2022-40879
CVE-2022-36593
CVE-2022-35151
CVE-2022-29349
CVE-2021-43734
all versions
A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileU
all versions
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
all versions
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/Online
all versions
A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWate
all versions
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.Online
all versions
kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.
all versions
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
all versions
kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
all versions
kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/Fil
all versions
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parame
all versions
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/Online
all versions
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on rel