FileRun has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.2 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-73699High· 7.2FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()52CVE-2026-73698High· 7.2FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…52CVE-2026-73694High· 7.2FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition52CVE-2026-73693High· 8.8FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler49
FileRun vulnerabilities
CVEs affecting FileRun, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-73694High· 7.2PoCFileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition
FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink uns…
CVE-2026-73699High· 7.2PoCFileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a position…
CVE-2026-73698High· 7.2PoCFileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…
FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…
CVE-2026-73693High· 8.8FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in th…