Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jirafeau MEDIUM 6.1
CVE-2026-1466

Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents could be exploited for cross…

Fix: 4.7.1+
Fix from $1,600 2026-01-28
Jirafeau MEDIUM 6.1
CVE-2025-7066

Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents could be exploited for cross…

Fix: 4.6.3+
Fix from $1,600 2025-07-04
Jirafeau MEDIUM 6.1
CVE-2024-12326

Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be exploited for cross site scriptin…

Fix: 4.6.1+
Fix from $1,600 2024-12-06
Jirafeau MEDIUM 6.1
CVE-2022-30110

The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scripting. An attacker could uploa…

Fix: 4.4.0+
Fix from $1,600 2022-05-17
Jirafeau HIGH 8.8
CVE-2018-11349

The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and …

Fix: 3.4.1+
Fix from $1,950 2018-07-07
Jirafeau MEDIUM 6.1
CVE-2018-11350

An issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting vulnerability via the name p…

Fix: 3.4.1+
Fix from $1,600 2018-07-07
Jirafeau MEDIUM 6.1
CVE-2018-11351

script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stored within the shared files de…

Fix: 3.4.1+
Fix from $1,600 2018-07-07
Jirafeau MEDIUM 6.1
CVE-2018-13408

An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an admin…

Fix: 3.4.1+
Fix from $1,600 2018-07-06
Jirafeau MEDIUM 6.1
CVE-2018-13409

An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an admin…

Fix: 3.4.1+
Fix from $1,600 2018-07-06