Releases294
Frequency2 weeks 3 days
Last Release
Stars14.9K
Beyond file syncing and sharing, a new way to organize your files with extensible file properties and flexible views

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 12.0.146.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with POST parámetro 'p' in '/api/v2.1/repos/{repo_id}/file/'.

< 12.0.146.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser by storing malicious payloads with PUT parámetro 'name' in '/api/v2.1/user/'.

= 9.0.65.4 MEDIUM

An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.

= 9.0.66.1 MEDIUM

The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

= 7.0.55.4 MEDIUM3.5 LOW

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

<= 6.2.115 MEDIUM

Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.