Alist

Vendor:

First CVE: Mar 12, 2022 · Active for 4 years

9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Alist over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2022
4 years ago
Most Recent CVE
Feb 4, 2026
171 days ago

CVE Severity & Scoring

Alist9 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple
Feb 4, 20268.828NONO
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default
Feb 4, 20267.426NONO
alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
Jun 7, 20238.825NONO
Alist v3.4.0 is vulnerable to Directory Traversal,
Dec 15, 20229.825NONO
AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.
May 23, 20237.523NONO
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).
Dec 12, 20228.822NONO
Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
Mar 12, 20226.121NONO
Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.
Dec 12, 20225.420NONO
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user
Sep 30, 20246.118NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Alist

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.5.115.40.5%00
3.4.029.31.1%00
3.15.117.51.1%00