Dulldusk develops a narrowly scoped web-based file management application, phpfilemanager, whose vulnerability profile centers on authentication and input-handling gaps characteristic of web applications. The durable signal reflects recurring weaknesses in cross-site scripting, missing critical-function authentication, and weak authentication mechanisms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dulldusk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53894CRITICAL phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft spe | Dec 16, 2025 | 9.8 | 32 | NO | NO |
CVE-2019-25632MEDIUM phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and fil | Mar 24, 2026 | 6.2 | 22 | NO | NO |
CVE-2024-5673MEDIUM Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could sen | Jun 6, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dulldusk.
Media articles that mention a CVE ID that affects a product developed by Dulldusk — matched by CVE ID, not by vendor name.