Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19201 | filebrowser allows Stored Cross-Site Scripting through the Markdown preview function |
Github GHSA |
GHSA-4wx8-5gm2-2j97 | filebrowser allows Stored Cross-Site Scripting through the Markdown preview function |
Thu, 10 Jul 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| CPEs | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
Thu, 26 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue. | |
| Title | File Browser has Stored Cross-Site Scripting vulnerability | |
| Weaknesses | CWE-79 CWE-80 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-26T15:01:19.861Z
Reserved: 2025-06-20T17:42:25.712Z
Link: CVE-2025-52902
Updated: 2025-06-26T15:01:12.409Z
Status : Analyzed
Published: 2025-06-26T15:15:23.687
Modified: 2025-07-10T01:09:35.847
Link: CVE-2025-52902
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:30Z
EUVD
Github GHSA