Filerise is a file-sharing and collaboration platform whose vulnerability footprint centers on access-control and input-handling flaws endemic to web-facing document-management services. The recurring weakness classes—improper access control, cross-site scripting, exposed file or directory permissions, and authorization bypasses—reflect the authentication and sanitization demands of a platform designed to manage and distribute sensitive files across users and teams. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Filerise over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33071HIGH FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml, .php5, .htaccess, an | Mar 20, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-33329HIGH FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handle | Mar 24, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-33072HIGH FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_this_key) is used for all cryptogr | Mar 20, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-62510HIGH FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibility/ownership to be inf | Oct 20, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-62509HIGH FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder hand | Oct 20, 2025 | 8.1 | 26 | NO | NO |
CVE-2026-25231HIGH FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access c | Feb 9, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33330HIGH FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user | Mar 24, 2026 | 7.1 | 21 | NO | NO |
CVE-2025-68116MEDIUM FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable | Dec 16, 2025 | 5.4 | 21 | NO | NO |
CVE-2026-25230MEDIUM FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form element | Feb 9, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-66403MEDIUM FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in | Dec 1, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Filerise.
Media articles that mention a CVE ID that affects a product developed by Filerise — matched by CVE ID, not by vendor name.