Roxyfileman is a file-management component that appears in web applications and content systems, where its disclosures center on a narrow but security-sensitive product scope. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurrent weakness classes including path traversal, unrestricted dangerous-file upload, and related input-handling flaws that grant attackers direct access to server filesystems and application data. Defenders should treat updates to this component as high-priority, especially in internet-facing contexts; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roxyfileman over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20526CRITICAL Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. | Mar 21, 2019 | 9.8 | 84 | NO | YES |
CVE-2018-20525CRITICAL Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. | Mar 21, 2019 | 9.1 | 52 | NO | YES |
CVE-2019-19731HIGH Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for | Dec 16, 2019 | 7.5 | 37 | NO | YES |
CVE-2022-40797CRITICAL Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any | Nov 9, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-7174CRITICAL Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Mov | Apr 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-12042HIGH Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter. | Jun 7, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roxyfileman.
Media articles that mention a CVE ID that affects a product developed by Roxyfileman — matched by CVE ID, not by vendor name.