Unisharp maintains the Laravel FileManager, a file-handling component for the Laravel framework with a narrowly scoped but strategically integrated exposure surface. The recurring vulnerability signal centers on classic file-operation weaknesses: code injection, path traversal, and unrestricted file uploads, all of which reflect the inherent risks of user-facing file-management functionality. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unisharp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40734MEDIUM UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June | Sep 14, 2022 | 6.5 | 34 | NO | YES |
CVE-2021-23814HIGH This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading.
An attacker may | Dec 17, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unisharp.
Media articles that mention a CVE ID that affects a product developed by Unisharp — matched by CVE ID, not by vendor name.