Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

File Manager HIGH 8.8
CVE-2024-8507

The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to mis…

Fix: 8.3.10+
Fix from $1,950 2024-10-16
File Manager HIGH 8.8
CVE-2024-8746

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'm…

Fix: 8.3.10+
Fix from $1,950 2024-10-16
File Manager MEDIUM 5.4
CVE-2024-8918

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to…

Fix: 8.3.10+
Fix from $1,600 2024-10-16
File Manager CRITICAL 9.8
CVE-2018-25105

The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions …

Fix: after 3.0
Fix from $2,300 2024-10-16
File Manager MEDIUM 6.8
CVE-2024-2654

The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup fun…

Fix: 7.2.6+
Fix from $1,600 2024-04-09
File Manager HIGH 8.8
CVE-2024-1538EPSS 11%

The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing…

Fix: 7.2.5+
Fix from $1,950 2024-03-21
File Manager HIGH 7.5
CVE-2024-0761

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient…

Fix: after 7.2.1
Fix from $1,950 2024-02-05
File Manager HIGH 8.8
CVE-2023-6846EPSS 16%

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_fileman…

Fix: after 8.3.4
Fix from $1,950 2024-02-05
File Manager MEDIUM 5.4
CVE-2021-24177

In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_f…

Fix: 7.1+
Fix from $1,600 2021-04-05
File Manager CRITICAL 9.8
CVE-2020-25213 KEVEPSS 97%

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it rename…

Fix: 6.9+
Fix from $2,300 2020-09-09
File Manager HIGH 7.5
CVE-2020-24312EPSS 16%

mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the …

Fix: after 6.4
Fix from $1,950 2020-08-26
File Manager HIGH 8.8
CVE-2018-16966

There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.

No fix yet
Fix from $1,950 2019-04-15
File Manager MEDIUM 6.1
CVE-2018-16967

There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.

No fix yet
Fix from $1,600 2019-04-15
File Manager MEDIUM 5.4
CVE-2018-16363

The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because s…

Patch available
Fix from $1,600 2018-09-07