Vendor
high
advisory
OS Command Injection in FileRun
2 TTPs 1 CVEFileRun versions prior to 2026.3.0 contain an OS command injection vulnerability via an improper redefinition of escapeshellcmd() that allows unauthenticated or authenticated users to execute arbitrary commands.
FileRun
web-vulnerability
rce
file-run
2t
1c
high
advisory
OS Command Injection in FileRun Thumbnail Generation
1 rule 1 TTP 1 CVEFileRun versions up to 2026.2.0 contain a command injection vulnerability in the thumbnail generation component allowing authenticated attackers to execute arbitrary code.
FileRun
remote-code-execution
command-injection
file-upload
1r
1t
1c