VulnSea

cloudreve has 16 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 9. The median CVSS is 6.4 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-863 (7). Most affected products: github.com/cloudreve/Cloudreve/v4 (12), github.com/cloudreve/Cloudreve (3), cloudreve (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
Last 90 days
15 prev 1

Products

  • github.com/cloudreve/Cloudreve/v4 12
  • github.com/cloudreve/Cloudreve 3
  • cloudreve 1
16
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

cloudreve vulnerabilities

CVEs affecting cloudreve, newest first. Open any entry for full detail, references, and exploit status.

16 CVEsRSS

CVE-2026-54563High· 7.1
3w ago

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.32%via GHSA
GO-2026-6289None
3w ago

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GO-2026-6287None
3w ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/…

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
GHSA-vx2m-jpxr-xv7wMedium· 5.3
4w ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-w8j7-39hp-8x59Medium
4w ago

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GO-2026-6106None
1mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

Sunlitcloudreve · github.com/cloudreve/Cloudrevevia OSV
CVE-2026-55495Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape th…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.26%via NVD
CVE-2026-55496Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to …

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.26%via NVD
CVE-2026-55497Medium· 6.5
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to subm…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.29%via NVD
CVE-2026-55499Medium· 4.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authentic…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.24%via NVD
CVE-2026-55502High· 7.1
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id value…

Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.23%via NVD
CVE-2026-62323Medium· 6.3
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or comp…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.17%via NVD
GHSA-v6w6-358x-2433Medium· 5.4
1mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
CVE-2026-54560High· 7.6
2mo ago

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.46%via GHSA
CVE-2026-54562Medium· 6.5
2mo ago

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.40%via GHSA
CVE-2026-25726High· 8.1
5mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, inclu…

Twilightcloudreve · cloudreveEPSS 0.38%via NVD
cloudreve vulnerabilities (CVEs) · VulnSea