Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-65346 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths. NVD description · AI analysis pending | 9.1 | <1% | PoC |
| — | |
| CVE-2025-65345 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-63307 | alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization. NVD description · AI analysis pending | 8.1 | <1% | PoC |
| — |