CVE-2026-37064CWE-203

CVE-2026-37064

Medium · published August 28, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
17.6
In the wild
Unconfirmed
What it is

User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00261 · 17.6th percentile
Weakness
CWE-203 · Observable Discrepancy
Published
2026-08-28T00:17Z
References (2)
EPSS history
Timeline
  • 27 AUG 00:00Z
    User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via…
    cvelistv5