CVE security advisories and vulnerability history for filebrowser by filebrowser.
33
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
28
Public exploits
With known exploit
7.1
Avg CVSS
2021–2026
Last updated
Overview
filebrowser has 33 published CVE records since 2021, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 28 have a known public exploit. The average CVSS base score across scored CVEs is 7.1.
This page aggregates every publicly disclosed vulnerability (CVE) affecting filebrowser, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of filebrowser's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High17
Medium10
Low1
3 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of filebrowser's CVEs are currently listed in CISA's KEV catalog.
Public exploits
28
28 of filebrowser's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every filebrowser version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about filebrowser vulnerabilities.
How many CVEs does filebrowser filebrowser have?
filebrowser filebrowser has 33 published CVE records since 2021.
How many filebrowser filebrowser CVEs are in CISA KEV?
None of filebrowser filebrowser's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for filebrowser filebrowser vulnerabilities?
Yes — 28 of filebrowser filebrowser's CVEs have a known public exploit.
Which versions of filebrowser filebrowser are affected?
261 distinct filebrowser filebrowser versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in filebrowser filebrowser CVEs?
filebrowser filebrowser's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')), CWE-269 (Improper Privilege Management), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
How many critical filebrowser filebrowser vulnerabilities are there?
filebrowser filebrowser has 2 critical and 17 high-severity CVEs.
What is the average severity of filebrowser filebrowser CVEs?
The average CVSS base score across filebrowser filebrowser's scored CVEs is 7.1.