gtsteffaniak has 3 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.5 (medium). Most affected products: github.com/gtsteffaniak/filebrowser/backend (2), github.com/gtsteffaniak/filebrowser (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- github.com/gtsteffaniak/filebrowser/backend 2
- github.com/gtsteffaniak/filebrowser 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-54910High· 7.7FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files42GHSA-r4v7-6wcg-ghj5Medium· 6.5FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks36CVE-2026-54685Medium· 5.3FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel29
gtsteffaniak vulnerabilities
CVEs affecting gtsteffaniak, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-54910High· 7.7FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
▾ Twilightgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.46%via GHSA
GHSA-r4v7-6wcg-ghj5Medium· 6.5FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks
FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks
▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowservia GHSA
CVE-2026-54685Medium· 5.3FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.47%via OSV