Codename065 / Download Manager
31 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-97338 | Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name | MEDIUM | 6.4 | Oct 2, 2026 |
| CVE-2026-92714 | Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter | MEDIUM | 6.5 | Sep 18, 2026 |
| CVE-2026-16685 | Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute | MEDIUM | 6.4 | Aug 1, 2026 |
| CVE-2026-14343 | Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes | MEDIUM | 6.4 | Jul 9, 2026 |
| CVE-2026-13733 | Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute | MEDIUM | 6.4 | Jul 1, 2026 |
| CVE-2026-4057 | Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal | MEDIUM | 4.3 | Apr 10, 2026 |
| CVE-2026-5357 | Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | MEDIUM | 6.4 | Apr 9, 2026 |
| CVE-2026-2571 | Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter | MEDIUM | 4.3 | Mar 19, 2026 |
| CVE-2026-1666 | Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter | MEDIUM | 6.1 | Feb 18, 2026 |
| CVE-2025-15364 | Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword | HIGH | 7.3 | Jan 6, 2026 |
| CVE-2025-13498 | Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure | MEDIUM | 4.3 | Dec 18, 2025 |
| CVE-2025-12177 | Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key | MEDIUM | 5.3 | Nov 8, 2025 |
| CVE-2025-10146 | Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter | MEDIUM | 6.1 | Sep 19, 2025 |
| CVE-2025-4367 | Download Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode | MEDIUM | 6.4 | Jun 19, 2025 |
| CVE-2025-3404 | Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion | HIGH | 8.8 | Apr 19, 2025 |
| CVE-2025-3056 | Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | MEDIUM | 5.4 | Apr 18, 2025 |
| CVE-2025-1785 | Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite | HIGH | 8.1 | Mar 13, 2025 |
| CVE-2024-11768 | Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected Files | MEDIUM | 5.3 | Dec 19, 2024 |
| CVE-2024-11740 | Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution | HIGH | 7.3 | Dec 19, 2024 |
| CVE-2024-6208 | Download Manager <= 3.2.97 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | MEDIUM | 6.4 | Jul 31, 2024 |
| CVE-2024-2098 | Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary | HIGH | 7.5 | Jun 13, 2024 |
| CVE-2024-1766 | Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting | MEDIUM | 5.4 | Jun 12, 2024 |
| CVE-2024-5266 | Download Manager <= 3.2.92 - Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes | MEDIUM | 6.4 | Jun 12, 2024 |
| CVE-2024-4001 | Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode | MEDIUM | 6.4 | Jun 5, 2024 |
| CVE-2024-4160 | Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode | MEDIUM | 6.4 | May 31, 2024 |
Showing 1 to 25 of 31 CVEs