Filebrowser is a modestly represented, self-hosted file-management application that occupies a prominent position in vulnerability disclosure despite a focused product footprint, reflecting its appeal as a lightweight alternative to larger content-management systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure centers on the application's web interface and privilege model, concentrating through weakness classes including cross-site scripting, command injection, incorrect authorization, and improper access control—issues characteristic of file-serving applications that must balance ease-of-use with security boundaries around filesystem and user-permission scoping. Defenders deploying this application in network-accessible contexts should prioritize timely patching and restrict exposure to trusted networks where possible. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Filebrowser over time
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46398HIGH A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via | Feb 4, 2022 | 8.8 | 42 | NO | YES |
CVE-2026-34528CRITICAL File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler | Apr 1, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-32760CRITICAL File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthent | Mar 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-35607HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35606HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in | Apr 7, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-34529CRITICAL File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview f | Apr 1, 2026 | 9.0 | 29 | NO | NO |
CVE-2025-64523HIGH File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an | Nov 12, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-35604HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a us | Apr 7, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-32759HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33 | Mar 20, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-25890HIGH File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated | Feb 9, 2026 | 8.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Filebrowser.
Media articles that mention a CVE ID that affects a product developed by Filebrowser — matched by CVE ID, not by vendor name.