Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Filebrowser

First CVE: Aug 31, 2021Active for: 5 yearsTotal CVEs: 34
46.5
VTI Score
High

Filebrowser is a modestly represented, self-hosted file-management application that occupies a prominent position in vulnerability disclosure despite a focused product footprint, reflecting its appeal as a lightweight alternative to larger content-management systems. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity. The recurring exposure centers on the application's web interface and privilege model, concentrating through weakness classes including cross-site scripting, command injection, incorrect authorization, and improper access control—issues characteristic of file-serving applications that must balance ease-of-use with security boundaries around filesystem and user-permission scoping. Defenders deploying this application in network-accessible contexts should prioritize timely patching and restrict exposure to trusted networks where possible. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
6.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Filebrowser over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2021
4 years ago
Most Recent CVE
Jul 12, 2026
12 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-46398HIGH
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via
Feb 4, 20228.842NOYES
CVE-2026-34528CRITICAL
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler
Apr 1, 20269.832NONO
CVE-2026-32760CRITICAL
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthent
Mar 20, 20269.832NONO
CVE-2026-35607HIGH
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1
Apr 7, 20268.829NONO
CVE-2026-35606HIGH
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in
Apr 7, 20267.529NONO
CVE-2026-34529CRITICAL
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview f
Apr 1, 20269.029NONO
CVE-2025-64523HIGH
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an
Nov 12, 20258.828NONO
CVE-2026-35604HIGH
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a us
Apr 7, 20268.127NONO
CVE-2026-32759HIGH
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33
Mar 20, 20268.127NONO
CVE-2026-25890HIGH
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated
Feb 9, 20268.127NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
41%
41%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.9%)
Network33 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (88.2%)
High4 (11.8%)
Unknown0 (0.0%)
User Interaction
None26 (76.5%)
Unknown0 (0.0%)
Required8 (23.5%)
Privileges Required
Low19 (55.9%)
High5 (14.7%)
None10 (29.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Filebrowser.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Filebrowser — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Filebrowser's Products

View all 3 CNAs →

Top CWEs