← Back

Alist

alist

Vendor: Alist Project • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Sep 30, 2024
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in...Show more
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.Show less
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Jun 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
May 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Alist v3.4.0 is vulnerable to Directory Traversal,
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Dec 12, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Dec 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).
2Alist Project
Alistgo
2Alist
Alist
Jun 17, 2026
Mar 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.