ZeroHour

CVE-2026-25230

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p11
Published
()
Modified
Description

FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user on active interaction. This vulnerability is fixed in 3.3.0.

Vendors
filerise
Products
filerise
Weakness
CWE-79, CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.