VulnSea

hfs vulnerabilities

CVEs whose affected-version data names the hfs package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-61505Medium· 5.3
2mo ago

Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter

Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the shared folders. Exploitation is constrained to files matching a n…

▾ Sunlitrejetto · hfsEPSS 0.52%via CVEORG
CVE-2026-61501Medium· 6.1
2mo ago

Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer

Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login with a crafted username that is written to the error log and execut…

▾ Sunlitrejetto · hfsEPSS 0.42%via CVEORG
CVE-2026-61503Medium· 5.3
2mo ago

Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences

Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can use this to confirm valid account names, including t…

▾ Sunlitrejetto · hfsEPSS 0.44%via CVEORG
CVE-2026-61500Critical· 9.8PoC
2mo ago

Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect …

▾ Abyssalrejetto · hfsEPSS 0.86%via CVEORG
CVE-2026-61504Medium· 5.4
2mo ago

Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing

Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser via the ?get=basic parameter. A user with upload permission - or an anonymous user on servers w…

▾ Sunlitrejetto · hfsEPSS 0.24%via CVEORG
CVE-2026-61502Medium· 4.3
2mo ago

Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests

Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configur…

▾ Sunlitrejetto · hfsEPSS 0.22%via CVEORG
hfs vulnerabilities (CVEs) · VulnSea