Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Seafile Server HIGH 8.7
CVE-2026-30587

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0…

Fix: 12.0.20+
Fix from $1,950 2026-03-25
Seafile Server MEDIUM 6.1
CVE-2025-65516

A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured wi…

Fix: 13.0.12+
Fix from $1,600 2025-12-04
Seafile MEDIUM 6.1
CVE-2025-41080

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code…

Fix: 12.0.14+
Fix from $1,600 2025-12-04
Seafile MEDIUM 6.1
CVE-2025-41079

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code…

Fix: 12.0.14+
Fix from $1,600 2025-12-04
Seafile MEDIUM 6.1
CVE-2023-28874

The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

No fix yet
Fix from $1,600 2023-12-09
Seafile MEDIUM 5.4
CVE-2023-28873

An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.

No fix yet
Fix from $1,600 2023-12-09
Seafile Server MEDIUM 5.9
CVE-2021-43820

Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve…

Fix: 8.0.8 / 8.0.15+
Fix from $1,600 2021-12-14
Seafile MEDIUM 5.4
CVE-2021-30146

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

Mitigation only
Fix from $1,600 2021-04-06
Seafile Client HIGH 7.8
CVE-2020-16143

The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.

No fix yet
Fix from $1,950 2020-07-29
Seafile HIGH 7.5
CVE-2013-7469

Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easie…

Fix: after 6.2.11
Fix from $1,950 2019-02-21
Seadroid HIGH 7.5
CVE-2019-8919

The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Ch…

Fix: after 2.2.13
Fix from $1,950 2019-02-18
Seafile Server HIGH 7.8
CVE-2014-5443

Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling u…

Fix: 3.1.0 / 3.1.2+
Fix from $1,950 2018-03-19