These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A path traversal vulnerability exists in Rejetto HFS versions 3.0.0 through 3.2.0. This vulnerability allows a remote unauthenticated attacker to read certain JSON files outside the shared folders by manipulating the lang query parameter. The exploitation is limited to files matching a specific naming and format pattern, which restricts the practical impact of the vulnerability.
Rejetto HFS 3.0.0 through 3.2.0 is vulnerable to stored cross-site scripting (XSS) via file names in its 'basic' web listing. An authenticated user with upload permissions, or an anonymous user if the upload folder is open, can store files with malicious script names. When another user views the listing, the script executes in their browser. This vulnerability requires user interaction but can lead to sig [truncated]
Rejetto HFS 3.0.0 through 3.2.0 is vulnerable to Cross-Site Request Forgery via GET requests. This allows remote attackers to perform administrative actions, including account creation and configuration changes, potentially leading to code execution. The attack can be carried out by causing a logged-in administrator's browser to navigate to a crafted URL or without credentials against default installation [truncated]
CVE-2026-61501 is a stored cross-site scripting (XSS) vulnerability in Rejetto HFS 3.0.0 through 3.2.0. The vulnerability allows a remote unauthenticated attacker to submit a failed login with a crafted username that is written to the error log. When an administrator views the logs, the crafted username executes JavaScript in the administrator's browser. This enables the attacker to create accounts or exe [truncated]
The CVE record for CVE-2026-61500 was published on 2026-07-13T18:16:29.903Z and has not been modified since then. The NVD entry is currently Deferred. Rejetto HFS versions 3.0.0 through 3.2.0 are affected by a critical vulnerability that allows remote attackers to forge valid administrator session cookies, leading to full administrative access and remote code execution. The vulnerability is caused by the [truncated]
CVE-2024-23692 affects Rejetto HTTP File Server (HFS) and is listed by CISA as a Known Exploited Vulnerability. The public record describes it as an improper neutralization of special elements used in a template engine. Because CISA added it to the KEV catalog on 2024-07-09 and set a remediation due date of 2024-07-30, defenders should treat it as a high-priority issue and move quickly to the vendor’s pat [truncated]
CVE-2014-6287 is listed by CISA in the Known Exploited Vulnerabilities catalog as a remote code execution issue affecting Rejetto HTTP File Server (HFS). CISA added the vulnerability on 2022-03-25 and set a remediation due date of 2022-04-15. The supplied guidance is to apply updates per vendor instructions.