CVE-2025-15585
Severity CVSS v4.0:
MEDIUM
Type:
CWE-89
SQL Injection
Publication date:
19/02/2026
Last modified:
19/02/2026
Description
Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration.
Impact
Base Score 4.0
6.70
Severity 4.0
MEDIUM



