File Manager
Filemanagerpro · 14 CVEs
File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload
Oct 16, 2024
File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download
Oct 16, 2024
File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload
Oct 16, 2024
File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload
Oct 16, 2024
File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal
Apr 9, 2024
File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion
Mar 21, 2024
File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload
Feb 5, 2024
File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames
Feb 5, 2024
WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)
Apr 5, 2021
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitr…
Sep 9, 2020
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacc…
Aug 26, 2020
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_ro…
Apr 15, 2019
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_ro…
Apr 15, 2019
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_…
Sep 7, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-8507 | File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload | HIGH | 0.25% | Oct 16, 2024 |
| CVE-2018-25105 | File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download | CRITICAL | 0.81% | Oct 16, 2024 |
| CVE-2024-8746 | File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload | HIGH | 0.65% | Oct 16, 2024 |
| CVE-2024-8918 | File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload | HIGH | 0.34% | Oct 16, 2024 |
| CVE-2024-2654 | File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal | MEDIUM | 0.91% | Apr 9, 2024 |
| CVE-2024-1538 | File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion | HIGH | 10.65% | Mar 21, 2024 |
| CVE-2023-6846 | File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload | HIGH | 15.87% | Feb 5, 2024 |
| CVE-2024-0761 | File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames | HIGH | 1.03% | Feb 5, 2024 |
| CVE-2021-24177 | WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS) | MEDIUM | 0.90% | Apr 5, 2021 |
| CVE-2020-25213 KEV | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsaf… | CRITICAL | 97.33% | Sep 9, 2020 |
| CVE-2020-24312 | mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability fo… | HIGH | 15.91% | Aug 26, 2020 |
| CVE-2018-16967 | There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | MEDIUM | 1.38% | Apr 15, 2019 |
| CVE-2018-16966 | There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | HIGH | 0.92% | Apr 15, 2019 |
| CVE-2018-16363 | The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transie… | MEDIUM | 1.38% | Sep 7, 2018 |
Showing 1 to 14 of 14 CVEs