Known Vulnerabilities for Alist by Alist Project
Listed below are 6 of the newest known vulnerabilities associated with "Alist" by "Alist Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-71066 json | In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Always remove class from active list bef... | Not Provided | 2026-01-13 | 2026-05-22 |
| CVE-2023-33498 json | alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file. | 8.8 - HIGH | 2023-06-07 | 2023-06-13 |
| CVE-2023-31726 json | AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information. | 7.5 - HIGH | 2023-05-23 | 2023-05-31 |
| CVE-2022-45970 json | Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board. | 5.4 - MEDIUM | 2022-12-12 | 2022-12-14 |
| CVE-2022-45969 json | Alist v3.4.0 is vulnerable to Directory Traversal, | 9.8 - CRITICAL | 2022-12-15 | 2022-12-20 |
| CVE-2022-45968 json | Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a ... | 8.8 - HIGH | 2022-12-12 | 2022-12-14 |
| CVE-2022-26533 json | Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist. | 6.1 - MEDIUM | 2022-03-12 | 2022-03-18 |