Filegator is a file-management and sharing application with a compact product portfolio, presenting a narrow but elevated exposure surface centered on access control and session handling. Its recurring vulnerability classes cluster around path-traversal conditions that bypass directory restrictions and session-fixation weaknesses that can compromise user authentication, both characteristic of web-facing file-access systems. Current severity, exploitation, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Filegator over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-63358HIGH FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion | Jul 21, 2026 | 7.3 | 29 | NO | NO |
CVE-2022-1850HIGH Path Traversal in GitHub repository filegator/filegator prior to 7.8.0. | May 24, 2022 | 8.1 | 27 | NO | NO |
CVE-2022-1849MEDIUM Session Fixation in GitHub repository filegator/filegator prior to 7.8.0. | May 24, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Filegator.
Media articles that mention a CVE ID that affects a product developed by Filegator — matched by CVE ID, not by vendor name.