VendorsLeefishfile_thingieall versions
Vulnerabilities

Leefish File Thingie

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-25471
FileThingie 2.5.7 Arbitrary File Upload via ft2.php
Published 2026-03-11 · Analyzed
9.8EPSS 0.009
CVE-2023-53942
File Thingie 2.5.7 Authenticated Arbitrary File Upload Remote Code Execution
Published 2025-12-18 · Analyzed
9.4EPSS 0.006
CVE-2026-30578
File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of the GET request to invoke arbitrary javascript code.
Published 2026-03-20 · Analyzed
6.5EPSS 0.002
CVE-2026-30579
File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload.
Published 2026-03-20 · Analyzed
6.5EPSS 0.002
CVE-2026-30580
File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system.
Published 2026-03-20 · Analyzed
4.3EPSS 0.006