Where
-Infinity
0

Vendor Risk Score

See how filebrowser compares to other vendors in security performance

View Risk Score →

Filebrowser Filebrowserfilebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink

Risk 60
Severity
8.2
First published (updated )

Filebrowser FileBrowser QuantumFileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

Risk 27
Severity
5.3
First published (updated )

Filebrowser Filebrowserfilebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete

Risk 17
Severity
2.3
First published (updated )

Filebrowser File BrowserFile Browser: Authentication Bypass via Proxy Auth Header Forgery

Risk 66
Severity
9.1
First published (updated )

Filebrowser FileBrowser QuantumFileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory

Risk 67
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/filebrowser/filebrowser/v2File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

Risk 79
Severity
8.8
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check

Risk 43
Severity
5.3
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser has an access rule bypass via HasPrefix without trailing separator in path matching

Risk 43
Severity
6.3
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser share links remain accessible after Share/Download permissions are revoked

Risk 43
Severity
8.2
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser has a Command Injection via Hook Runner

Risk 66
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/filebrowser/filebrowser/v2File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection

Risk 43
Severity
6.9
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution

Risk 86
Severity
9.8
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file

Risk 74
Severity
9
First published (updated )

go/https://github.com/filebrowser/filebrowserFile Browser has an Authorization Policy Bypass in its Public Share Download Flow

Risk 27
Severity
6.5
EPSS
0.01%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter

Risk 27
Severity
6.5
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/filebrowser/filebrowser/v2File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin

Risk 61
Severity
10
EPSS
0.01%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely

Risk 43
Severity
5.3
EPSS
0.24%
First published (updated )

Filebrowser FilebrowserFileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)

Risk 52
Severity
8.9
EPSS
0.04%
First published (updated )

Filebrowser FilebrowserFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info

Risk 31
Severity
7.5
EPSS
0.07%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser: TUS Delete Endpoint Bypasses Delete Permission Check

Risk 47
Severity
9.1
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/filebrowser/filebrowser/v2File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory

Risk 29
Severity
7.1
EPSS
0.04%
First published (updated )

Gtsteffaniak Filebrowser QuantumFileBrowser Quantum: Password Protection Not Enforced on Shared File Links

Risk 34
Severity
7.1
EPSS
0.03%
First published (updated )

FileBrowserFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

Risk 43
Severity
8.1
EPSS
0.01%
First published (updated )

File Browser File BrowserFile Browser has an Authentication Bypass in User Password Update

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )

File Browser File BrowserFile Browser vulnerable to Username Enumeration via Timing Attack in /api/login

Risk 19
Severity
5.3
EPSS
0.18%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Filebrowser FilebrowserFileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function

Risk 79
Severity
8.8
First published (updated )

File Browser File BrowserFileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout

Risk 86
Severity
9.8
First published (updated )

File Browser File BrowserFile Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processing

Risk 44
Severity
7.7
First published (updated )

go/github.com/filebrowser/filebrowserFile Browser Insecurely Handles Passwords

Risk 43
Severity
7.5
First published (updated )

go/github.com/filebrowser/filebrowserFile Browser's Password Protection of Links Vulnerable to Bypass

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203