Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-4367 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions… Download Manager 3.3.19+ Fix from $1,6002025-06-19 HIGH 8.1 CVE-2025-1785 The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' ac… Download Manager 3.3.09+ Fix from $1,9502025-03-13 MEDIUM 6.3 CVE-2024-56217 Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Le… Download Manager 3.3.04+ Fix from $1,6002024-12-31 MEDIUM 5.3 CVE-2024-11768 The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on… Download Manager 3.3.04+ Fix from $1,6002024-12-19 HIGH 7.3 CVE-2024-11740 The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is du… Download Manager 3.3.04+ Fix from $1,9502024-12-19 MEDIUM 5.4 CVE-2024-8444 The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting. Download Manager 3.3.00+ Fix from $1,6002024-10-30 MEDIUM 5.4 CVE-2024-6208 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions… Download Manager 3.2.98+ Fix from $1,6002024-07-31 HIGH 7.5 CVE-2024-2098 The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLib… Download Manager 3.2.90+ Fix from $1,9502024-06-13 MEDIUM 5.4 CVE-2024-1766 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including… Download Manager 3.2.87+ Fix from $1,6002024-06-12 MEDIUM 5.4 CVE-2024-5266 The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm… Download Manager 3.2.94+ Fix from $1,6002024-06-12 MEDIUM 5.4 CVE-2024-4160 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions… Download Manager 3.2.90+ Fix from $1,6002024-05-31 HIGH 7.5 CVE-2024-32131 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affe… Download Manager 3.2.83+ Fix from $1,9502024-05-17 MEDIUM 5.4 CVE-2024-29114 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XS… Download Manager 3.2.85+ Fix from $1,6002024-03-19 MEDIUM 5.4 CVE-2023-6954 The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and i… Download Manager after 3.2.85 Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2023-6785 The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and includ… Download Manager 3.2.85+ Fix from $1,6002024-03-13 HIGH 7.5 CVE-2023-6421 The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. Download Manager 3.2.83+ Fix from $1,9502024-01-01 MEDIUM 5.4 CVE-2023-2305 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' sho… Download Manager 3.2.71+ Fix from $1,6002023-06-09 MEDIUM 6.5 CVE-2023-1524 The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master ke… Download Manager 3.2.71+ Fix from $1,6002023-05-30 HIGH 7.5 CVE-2023-1809 The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbit… Download Manager 6.3.0+ Fix from $1,9502023-05-02 MEDIUM 6.1 CVE-2022-45836 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. Download Manager 3.2.60+ Fix from $1,6002023-04-18 MEDIUM 5.4 CVE-2022-4476 The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the… Download Manager 3.2.62+ Fix from $1,6002023-01-16 HIGH 8.8 CVE-2022-2431 The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficie… Download Manager after 3.2.50 Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-2436 The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to… Download Manager 3.2.50+ Fix from $1,9502022-09-06 HIGH 8.8 CVE-2022-36288 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. Download Manager after 3.2.48 Fix from $1,9502022-08-23 MEDIUM 5.4 CVE-2022-34658 Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. Download Manager after 3.2.48 Fix from $1,6002022-08-23 HIGH 8.8 CVE-2022-34347 Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. Download Manager after 3.2.48 Fix from $1,9502022-08-22 HIGH 7.5 CVE-2022-2362 The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes … Download Manager 3.2.50+ Fix from $1,9502022-08-22 MEDIUM 5.4 CVE-2022-2101 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and inclu… Download Manager after 3.2.46 Fix from $1,6002022-07-18 MEDIUM 6.1 CVE-2022-2168 The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboar… Download Manager 3.2.44+ Fix from $1,6002022-07-17 MEDIUM 6.1 CVE-2022-1985 The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to ins… Download Manager after 3.2.42 Fix from $1,6002022-06-13