cloudreve CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

cloudreve vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to cloudreve, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-25726 Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. These secrets are generated upon first startup and persisted in the database. An attacker can exploit this by obtaining the administrator's account creation time (via public API endpoints) to narrow the search window for the [email protected] 8.1 0.02% 2026-04-03 2026-04-13
CVE-2022-32167 Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation. [email protected] 5.4 0.21% 2022-09-20 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence