Filerun is a file-synchronization and sharing platform that, despite a narrow product scope, occupies a prominent role in content-management and document-collaboration deployments. The observed vulnerability exposure centers on SQL injection and related input-handling weaknesses that reflect the product's database-driven architecture; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Filerun over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14738CRITICAL FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module | Sep 30, 2017 | 9.8 | 41 | NO | YES |
CVE-2022-47532CRITICAL FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users§ion=cpanel&page=list request. | Dec 22, 2023 | 9.8 | 25 | NO | NO |
CVE-2007-2469HIGH SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter. | May 2, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-2470MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) modu | May 2, 2007 | 5.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Filerun.
Media articles that mention a CVE ID that affects a product developed by Filerun — matched by CVE ID, not by vendor name.