CVE-2018-14728: Tecrail Responsive Filemanager

Critical severity, CVSS 9.8. EPSS: 76.3% chance of exploitation in the next 30 days.

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

Affected products

  • Tecrail Responsive Filemanager: version 9.13.1 only

Published 2018-08-03. Last modified 2026-06-17.