FileRun / FileRun
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-73699 | FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms() | HIGH | 8.6 | Sep 10, 2026 |
| CVE-2026-73698 | FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action | HIGH | 8.6 | Sep 10, 2026 |
| CVE-2026-73694 | FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition | HIGH | 8.6 | Sep 10, 2026 |
| CVE-2026-73693 | FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler | HIGH | 8.7 | Sep 10, 2026 |
| CVE-2026-14863 | FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection | HIGH | 8.7 | Aug 11, 2026 |
| CVE-2022-47532 | FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users§ion=cpanel&page=list request. | CRITICAL | 9.8 | Dec 22, 2023 |
| CVE-2017-14738 | FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside t… | CRITICAL | 9.8 | Sep 29, 2017 |
| CVE-2007-2470 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via t… | MEDIUM | 5.8 | May 2, 2007 |
| CVE-2007-2469 | SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter. | HIGH | 7.5 | May 2, 2007 |
Showing 1 to 5 of 5 CVEs