Where
-Infinity
0

Filebrowser Filebrowserfilebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink

Risk 60
Severity
8.2
First published (updated )

Filebrowser Filebrowserfilebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete

Risk 17
Severity
2.3
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

Risk 79
Severity
8.8
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check

Risk 43
Severity
5.3
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser has an access rule bypass via HasPrefix without trailing separator in path matching

Risk 43
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/filebrowser/filebrowser/v2File Browser share links remain accessible after Share/Download permissions are revoked

Risk 43
Severity
8.2
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser has a Command Injection via Hook Runner

Risk 66
Severity
7.5
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection

Risk 43
Severity
6.9
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser's Signup Grants Execution Permissions When Default Permissions Includes Execution

Risk 86
Severity
9.8
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file

Risk 74
Severity
9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/https://github.com/filebrowser/filebrowserFile Browser has an Authorization Policy Bypass in its Public Share Download Flow

Risk 27
Severity
6.5
EPSS
0.01%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter

Risk 27
Severity
6.5
EPSS
0.01%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin

Risk 61
Severity
10
EPSS
0.01%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely

Risk 43
Severity
5.3
EPSS
0.24%
First published (updated )

Filebrowser FilebrowserFileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)

Risk 52
Severity
8.9
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Filebrowser FilebrowserFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info

Risk 31
Severity
7.5
EPSS
0.07%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser: TUS Delete Endpoint Bypasses Delete Permission Check

Risk 47
Severity
9.1
EPSS
0.05%
First published (updated )

go/github.com/filebrowser/filebrowser/v2File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory

Risk 29
Severity
7.1
EPSS
0.04%
First published (updated )

FileBrowserFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL

Risk 43
Severity
8.1
EPSS
0.01%
First published (updated )

File Browser File BrowserFile Browser has an Authentication Bypass in User Password Update

Risk 25
Severity
5.4
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

File Browser File BrowserFile Browser vulnerable to Username Enumeration via Timing Attack in /api/login

Risk 19
Severity
5.3
EPSS
0.18%
First published (updated )

Filebrowser FilebrowserFileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function

Risk 79
Severity
8.8
First published (updated )

File Browser FilebrowserFile Browser: Command Execution not Limited to Scope

Risk 65
Severity
8.1
First published (updated )

File Browser File BrowserFile Browser Allows Execution of Shell Commands That Can Spawn Other Commands

Risk 65
Severity
8.1
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203