CVE-2025-15585: Fileflows
Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration.
Affected products
- Fileflows Fileflows: before 25.05.2 (fixed in 25.05.2)
Published 2026-02-19. Last modified 2026-06-17.