LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-30934

CVE-2026-30934 - Vulnerability Analysis

HighCVSS: 8.9

Last Updated: March 11, 2026

FileBrowser Quantum - Stored XSS

Published: March 10, 2026Updated: March 11, 2026Remote Exploitable

Overview

FileBrowser Quantum < 1.3.1-beta and < 1.2.2-stable contains a stored XSS caused by improper escaping of share metadata fields in /public/share/<hash>, letting attackers execute scripts when victims visit the share URL, exploit requires victim to visit malicious share link.

Severity & Score

Severity: High
CVSS Score: 8.9
EPSS Score: 3.8%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary scripts in victims' browsers, potentially stealing cookies or performing actions on their behalf.

Mitigation

Update to versions 1.3.1-beta or 1.2.2-stable or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 10, 2026

🟠 CVE-2026-30934 - High (8.9) FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/ without context-aw... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30934/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-30934
Severity
High
CVSS Score
8.9
Type
stored_xss
Status
unconfirmed
EPSS
3.8%
Social Posts
1

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

EPSS Score

3.8%Probability of exploitation in the next 30 days