CVE-2026-30934Disclosure(filebrowser / filebrowser)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch filebrowser filebrowser systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of html/template, allowing injected scripts to execute when victims visit the share URL. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filebrowser

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-10); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
filebrowser

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-18: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-18: 203-1003-18
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-102
Disclosure1Patch1
2026-03-182
Disclosure2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30934 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., titl… https://www.cve.org/CVERecord?id=CVE-2026-30934 ----- Traducción: CVE-2026-30934 Fil… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑30934, reporting a stored XSS flaw in older versions of FileBrowser Quantum, but offers no PoC, exploitation details, or remediation information.

    0000037
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30934 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., titl… https://www.cve.org/CVERecord?id=CVE-2026-30934

    Post summary

    Announcement of a stored XSS vulnerability in FileBrowser Quantum affecting versions prior to 1.3.1-beta and 1.2.2-stable through share metadata fields.

    00000191
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30934: HIGH] Vulnerability in FileBrowser Quantum &lt;1.3.1-beta and &lt;1.2.2-stable allows Stored XSS via share metadata fields. Update to 1.3.1-beta or 1.2.2-stable to fix this issue.#cve,CVE-2026-30934,#cybersecurity https://cvefind.com/CVE-2026-30934

    Post summary

    The CVE-2026-30934 vulnerability causes stored XSS in older FileBrowser Quantum releases; updating to the mentioned versions resolves the issue.

    0000035
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30934 - High FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are ... https://www.thehackerwire.com/vulnerability/CVE-2026-30934/ https://t.co/dUSHSLCTqK

    Post summary

    The post announces a Stored XSS vulnerability (CVE-2026-30934) affecting specific FileBrowser Quantum versions, providing technical details but no PoC, exploit, patch, or active exploitation evidence.

    0000032
    133 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfilebrowserfilebrowser---
Appfilebrowserfilebrowser1.2.1--
Appfilebrowserfilebrowser1.3.0--

Explore more