CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-54414

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
1.09%
62th pct
KEV
No
Class
oss containerizable
CWE-22, CWE-434

Description

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %).

References

Status: profiled · ingested 2026-08-10T18:00:50.000Z