FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user on active interaction. This vulnerability is fixed in 3.3.0.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Error311
Error311 filerise |
|
| Vendors & Products |
Error311
Error311 filerise |
Mon, 09 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user on active interaction. This vulnerability is fixed in 3.3.0. | |
| Title | FileRise affected by HTML Injection using color property in file tags | |
| Weaknesses | CWE-116 CWE-79 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-09T18:32:09.795Z
Updated: 2026-02-10T16:01:32.571Z
Reserved: 2026-01-30T14:44:47.328Z
Link: CVE-2026-25230
No data.
Status : Awaiting Analysis
Published: 2026-02-09T20:15:56.700
Modified: 2026-02-09T21:55:30.093
Link: CVE-2026-25230
No data.