Filebrowser
Vendor:
First CVE: Aug 31, 2021 · Active for 4 years
34
Total CVEs
Bottom 1%
6.8
Avg CVEs / Year
Bottom 1%
7.2
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Filebrowser over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2021
4 years ago
Most Recent CVE
Jul 12, 2026
12 days ago
CVE Severity & Scoring
Filebrowser34 CVEs
41%
41%
15%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.9%)
Network33 (97.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (88.2%)
High4 (11.8%)
Unknown0 (0.0%)
User Interaction
None26 (76.5%)
Unknown0 (0.0%)
Required8 (23.5%)
Privileges Required
Low19 (55.9%)
High5 (14.7%)
None10 (29.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46398HIGH A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via | Feb 4, 2022 | 8.8 | 42 | NO | YES |
CVE-2026-34528CRITICAL File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler | Apr 1, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-32760CRITICAL File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthent | Mar 20, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-35607HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35606HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in | Apr 7, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-34529CRITICAL File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview f | Apr 1, 2026 | 9.0 | 29 | NO | NO |
CVE-2025-64523HIGH File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an | Nov 12, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-35604HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a us | Apr 7, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-32759HIGH File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33 | Mar 20, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-25890HIGH File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated | Feb 9, 2026 | 8.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.9% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Filebrowser
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.39.0 | 1 | 9.8 | 0.5% | 0 | 0 |
| 2.38.0 | 1 | 6.5 | 0.4% | 0 | 0 |
| 2.32.0 | 2 | 8.0 | 0.9% | 0 | 0 |
| 1.3.0 | 2 | 6.5 | 0.4% | 0 | 0 |
| 1.2.1 | 2 | 6.5 | 0.4% | 0 | 0 |