files vulnerabilities
CVEs whose affected-version data names the files package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-54790Medium· 6.5Files is a module for managing files inside spaces and user profiles
Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized dat…
▾ Sunlithumhub · filesEPSS 0.31%via NVD
CVE-2025-54789Medium· 6.1Files is a module for managing files inside spaces and user profiles
Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of arbitrary JavaScript, which can lead to Browser JS code exe…
▾ Sunlithumhub · filesEPSS 0.27%via NVD