Known Vulnerabilities for Php File Browser Script by Php File Browser Script Project
Listed below are 1 of the newest known vulnerabilities associated with "Php File Browser Script" by "Php File Browser Script Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61504 json | Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be force... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-61456 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/medi... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-61448 json | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-55746 json | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-47119 json | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrar... | Not Provided | 2026-05-27 | 2026-07-14 |
| CVE-2026-46489 json | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file ... | Not Provided | 2026-06-11 | 2026-06-12 |
| CVE-2026-46426 json | Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does no... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-44587 json | CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_den... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-42451 json | Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in Grimm... | Not Provided | 2026-05-08 | 2026-05-12 |
| CVE-2026-40548 json | SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upl... | Not Provided | 2026-06-01 | 2026-06-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php File Browser Script Project | Php File Browser Script | 1.0 |