Cloudreve

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 11
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-62323

    Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored

    Last Modified: Jul 31, 2026
    Published: Jul 31, 2026

    CVE-2026-55502

    Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials

    Last Modified: Jul 31, 2026
    Published: Jul 31, 2026

    CVE-2026-55499

    Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients

    Last Modified: Jul 31, 2026
    Published: Jul 31, 2026

    CVE-2026-55497

    Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)

    Last Modified: Jul 31, 2026
    Published: Jul 31, 2026

    CVE-2026-55496

    Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate

    Last Modified: Jul 31, 2026
    Published: Jul 31, 2026
    Items Per Page
    Cloudreve Vulnerabilities & Security CVEs | CVE-DB