tecrail CVE Vulnerabilities & Metrics

Focus on tecrail vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About tecrail Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tecrail. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tecrail CVEs: 20
Earliest CVE date: 03 Aug 2018, 18:29 UTC
Latest CVE date: 28 Jun 2023, 15:15 UTC

Latest CVE reference: CVE-2022-44276

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tecrail CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.77

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 14
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS tecrail CVEs

These are the five CVEs with the highest CVSS scores for tecrail, sorted by severity first and recency.

All CVEs for tecrail

CVE-2022-44276 tecrail vulnerability CVSS: 0 28 Jun 2023, 15:15 UTC

In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

CVE-2022-46604 tecrail vulnerability CVSS: 0 02 Feb 2023, 13:15 UTC

An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.

CVE-2017-20145 tecrail vulnerability CVSS: 0 25 Jul 2022, 05:15 UTC

A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2020-11106 tecrail vulnerability CVSS: 4.3 30 Mar 2020, 22:15 UTC

An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a payload in the type parameter, and then returns to the dialog.php page. This occurs because ajax_calls.php was also able to set the $_SESSION['RF']["view_type"] variable, but there it wasn't sanitized.

CVE-2020-10567 tecrail vulnerability CVSS: 7.5 14 Mar 2020, 14:15 UTC

An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

CVE-2020-10212 tecrail vulnerability CVSS: 7.5 07 Mar 2020, 00:15 UTC

upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.

CVE-2018-20795 tecrail vulnerability CVSS: 5.0 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.

CVE-2018-20794 tecrail vulnerability CVSS: 5.0 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.

CVE-2018-20793 tecrail vulnerability CVSS: 5.0 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.

CVE-2018-20792 tecrail vulnerability CVSS: 5.0 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.

CVE-2018-20791 tecrail vulnerability CVSS: 4.3 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action.

CVE-2018-20790 tecrail vulnerability CVSS: 6.4 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.

CVE-2018-20789 tecrail vulnerability CVSS: 6.4 25 Feb 2019, 06:29 UTC

tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.

CVE-2018-18867 tecrail vulnerability CVSS: 5.0 31 Oct 2018, 05:29 UTC

An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.

CVE-2018-18062 tecrail vulnerability CVSS: 4.3 10 Oct 2018, 21:29 UTC

An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.

CVE-2018-18061 tecrail vulnerability CVSS: 6.4 10 Oct 2018, 21:29 UTC

An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.

CVE-2018-15536 tecrail vulnerability CVSS: 5.8 24 Aug 2018, 19:29 UTC

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

CVE-2018-15535 tecrail vulnerability CVSS: 5.0 24 Aug 2018, 19:29 UTC

/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.

CVE-2018-15495 tecrail vulnerability CVSS: 5.0 18 Aug 2018, 02:29 UTC

/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.

CVE-2018-14728 tecrail vulnerability CVSS: 7.5 03 Aug 2018, 18:29 UTC

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.