CVE-2019-7174: Roxyfileman Roxy Fileman

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.

Affected products

Published 2019-04-09. Last modified 2026-06-17.