VulnSea

filerun vulnerabilities

CVEs whose affected-version data names the filerun package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

8 CVEsRSS

CVE-2026-73694High· 7.2PoC
1w ago

FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink uns…

MidnightFileRun · FileRunEPSS 1.8%via CVEORG
CVE-2026-73699High· 7.2PoC
1w ago

FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a position…

MidnightFileRun · FileRunEPSS 0.54%via CVEORG
CVE-2026-73698High· 7.2PoC
1w ago

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

MidnightFileRun · FileRunEPSS 0.45%via NVD
CVE-2026-73693High· 8.8
1w ago

FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in th…

TwilightFileRun · FileRunEPSS 1.8%via CVEORG
CVE-2021-35506Medium· 6.1
4y ago

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

Sunlitafian · filerunEPSS 0.74%via NVD
CVE-2021-35504High· 7.2
4y ago

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

Twilightafian · filerunEPSS 3.2%via NVD
CVE-2021-35503Medium· 6.1
4y ago

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

Sunlitafian · filerunEPSS 0.74%via NVD
CVE-2021-35505High· 7.2
4y ago

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

Twilightafian · filerunEPSS 2.8%via NVD
filerun vulnerabilities (CVEs) · VulnSea