Stored XSS Vulnerability in FileRise Web File Manager
CVE-2025-68116
Key Information:
Badges
What is CVE-2025-68116?
FileRise, a self-hosted web file manager and WebDAV server, is affected by a vulnerability that allows stored Cross-Site Scripting (XSS) due to improper handling of user-uploaded files. Specifically, versions prior to 2.7.1 do not adequately sanitize browser-renderable uploads, enabling attackers to upload crafted SVG or HTML files. When victims access shared links or direct download paths associated with these unsafe uploads, it can lead to JavaScript execution in their browsers, posing a significant security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FileRise < 2.7.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
