Tecrail / Responsive Filemanager
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-5482 | Remote Code Execution via Unrestricted File Upload in Responsive FileManager | CRITICAL | 9.3 | Jun 15, 2026 |
| CVE-2022-44276 | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | CRITICAL | 9.8 | Jun 28, 2023 |
| CVE-2022-46604 | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leadin… | HIGH | 8.8 | Feb 2, 2023 |
| CVE-2017-20145 | Tecrail Responsive Filemanger path traversal | CRITICAL | 9.8 | Jul 25, 2022 |
| CVE-2020-11106 | An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if… | MEDIUM | 6.1 | Mar 30, 2020 |
| CVE-2020-10567 | An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validati… | CRITICAL | 9.8 | Mar 14, 2020 |
| CVE-2020-10212 | upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possib… | CRITICAL | 9.8 | Mar 6, 2020 |
| CVE-2018-20795 | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action i… | HIGH | 7.5 | Feb 25, 2019 |
| CVE-2018-20794 | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, th… | HIGH | 7.5 | Feb 25, 2019 |
| CVE-2018-20793 | tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, th… | HIGH | 7.5 | Feb 25, 2019 |
| CVE-2018-20792 | tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in… | HIGH | 7.5 | Feb 25, 2019 |
| CVE-2018-20791 | tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action. | MEDIUM | 6.1 | Feb 25, 2019 |
| CVE-2018-20790 | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass throu… | HIGH | 7.5 | Feb 25, 2019 |
| CVE-2018-20789 | tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass… | HIGH | 7.5 | Feb 25, 2019 |
| CVE-2018-18867 | An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix fo… | HIGH | 8.6 | Oct 31, 2018 |
| CVE-2018-18062 | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web sc… | MEDIUM | 6.1 | Oct 10, 2018 |
| CVE-2018-18061 | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the abil… | HIGH | 7.5 | Oct 10, 2018 |
| CVE-2018-15536 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of c… | MEDIUM | 5.5 | Aug 24, 2018 |
| CVE-2018-15535 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted dire… | HIGH | 7.5 | Aug 24, 2018 |
| CVE-2018-15495 | /filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec c… | HIGH | 7.5 | Aug 18, 2018 |
| CVE-2018-14728 | upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. | CRITICAL | 9.8 | Aug 3, 2018 |
Showing 1 to 20 of 20 CVEs