Filemanagerpro / File Manager
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-8507 | File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload | HIGH | 8.8 | Oct 16, 2024 |
| CVE-2018-25105 | File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download | CRITICAL | 9.8 | Oct 16, 2024 |
| CVE-2024-8746 | File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload | HIGH | 8.8 | Oct 16, 2024 |
| CVE-2024-8918 | File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload | HIGH | 7.4 | Oct 16, 2024 |
| CVE-2024-2654 | File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal | MEDIUM | 6.8 | Apr 9, 2024 |
| CVE-2024-1538 | File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion | HIGH | 8.8 | Mar 21, 2024 |
| CVE-2023-6846 | File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload | HIGH | 8.8 | Feb 5, 2024 |
| CVE-2024-0761 | File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames | HIGH | 8.1 | Feb 5, 2024 |
| CVE-2021-24177 | WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS) | MEDIUM | 5.4 | Apr 5, 2021 |
| CVE-2020-25213 KEV | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsaf… | CRITICAL | 10.0 | Sep 9, 2020 |
| CVE-2020-24312 | mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability fo… | HIGH | 7.5 | Aug 26, 2020 |
| CVE-2018-16967 | There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | MEDIUM | 6.1 | Apr 15, 2019 |
| CVE-2018-16966 | There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | HIGH | 8.8 | Apr 15, 2019 |
| CVE-2018-16363 | The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transie… | MEDIUM | 5.4 | Sep 7, 2018 |
Showing 1 to 14 of 14 CVEs