afian CVE Vulnerabilities & Metrics

Focus on afian vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About afian Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with afian. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total afian CVEs: 14
Earliest CVE date: 06 Mar 2018, 19:29 UTC
Latest CVE date: 06 Dec 2023, 01:15 UTC

Latest CVE reference: CVE-2023-28876

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical afian CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.85

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 2
4.0-6.9 11
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS afian CVEs

These are the five CVEs with the highest CVSS scores for afian, sorted by severity first and recency.

All CVEs for afian

CVE-2023-28876 afian vulnerability CVSS: 0 06 Dec 2023, 01:15 UTC

A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users.

CVE-2023-28875 afian vulnerability CVSS: 0 06 Dec 2023, 01:15 UTC

A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.

CVE-2022-30469 afian vulnerability CVSS: 6.5 06 Jun 2022, 21:15 UTC

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

CVE-2022-30470 afian vulnerability CVSS: 7.5 02 Jun 2022, 14:15 UTC

In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user.

CVE-2021-35506 afian vulnerability CVSS: 4.3 05 Oct 2021, 13:15 UTC

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

CVE-2021-35505 afian vulnerability CVSS: 6.5 05 Oct 2021, 12:15 UTC

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.

CVE-2021-35504 afian vulnerability CVSS: 6.5 05 Oct 2021, 12:15 UTC

Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.

CVE-2021-35503 afian vulnerability CVSS: 4.3 05 Oct 2021, 12:15 UTC

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

CVE-2019-12905 afian vulnerability CVSS: 4.3 20 Jun 2019, 16:15 UTC

FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed in FileRun 2019.06.01.

CVE-2019-12459 afian vulnerability CVSS: 5.0 30 May 2019, 14:29 UTC

FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.

CVE-2019-12458 afian vulnerability CVSS: 5.0 30 May 2019, 14:29 UTC

FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.

CVE-2019-12457 afian vulnerability CVSS: 5.0 30 May 2019, 14:29 UTC

FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.

CVE-2018-7735 afian vulnerability CVSS: 6.5 06 Mar 2018, 19:29 UTC

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.

CVE-2018-7734 afian vulnerability CVSS: 6.5 06 Mar 2018, 19:29 UTC

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.