← Back

CVE-2026-25230

nvd nist
Published: Feb 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user on active interaction. This vulnerability is fixed in 3.3.0.

Affected (1)

Products: Filerise: Filerise
1 product
Filerise
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.3.0

Timeline

No history available yet.