← Back

Phpfilemanager

phpfilemanager

Vendor: Dulldusk • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dulldusk
1Phpfilemanager
Jun 17, 2026
Mar 24, 2026
6.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET...Show more
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.Show less
1Dulldusk
1Phpfilemanager
Jun 17, 2026
Dec 16, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e...Show more
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.Show less
1Dulldusk
1Phpfilemanager
Jun 17, 2026
Jun 6, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload...Show more
Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.Show less