Filecloud is a focused file-sharing and content-collaboration platform that has accumulated vulnerability disclosures concentrated in its core product. The recurring weakness classes—cross-site request forgery, sensitive information exposure, improper access control, and code injection—reflect the authentication, session handling, and input-processing demands of web-facing document-management systems, and the vendor's disclosures tend to acquire public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Filecloud over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25241HIGH In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). | Feb 16, 2022 | 8.8 | 40 | NO | YES |
CVE-2022-25242HIGH In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF). | Feb 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-39833HIGH FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request. | Nov 23, 2022 | 7.2 | 25 | NO | NO |
CVE-2016-6578HIGH CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions | Jul 13, 2018 | 8.8 | 22 | NO | NO |
CVE-2022-1958MEDIUM A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access control | Jun 15, 2022 | 6.5 | 19 | NO | NO |
CVE-2022-24633MEDIUM All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could i | Feb 24, 2022 | 5.3 | 19 | NO | NO |
CVE-2020-26524MEDIUM CodeLathe FileCloud before 20.2.0.11915 allows username enumeration. | Oct 2, 2020 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Filecloud.
Media articles that mention a CVE ID that affects a product developed by Filecloud — matched by CVE ID, not by vendor name.