Product
alexusmai laravel file manager
5 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-65346
CVE-2025-65345
CVE-2025-63307
CVE-2022-40734
CVE-2021-23814
<= 3.3.1
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly
<= 3.3.1
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an att
all versions
alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload,
<= 2.5.1
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read
>= 0.0.0
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently valida