Skip to content
Noroxi

filemanagerpro records

14 published records for vendor filemanagerpro.

All records

14 records
  • The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    filemanagerpro · file managerSep 9, 2020

  • File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 16%

    filemanagerpro · file managerFeb 5, 2024

  • File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download

    CriticalCVSS 9.8No exploitEPSS 1%

    filemanagerpro · file managerOct 16, 2024

  • CVE-2024-1538
    38Monitor

    File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion

    HighCVSS 8.8No exploitEPSS 11%

    filemanagerpro · file managerMar 21, 2024

  • mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file.

    HighCVSS 7.5Proof of conceptEPSS 16%

    filemanagerpro · file managerAug 26, 2020

  • There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parame

    HighCVSS 8.8No exploitEPSS 1%

    filemanagerpro · file managerApr 15, 2019

  • CVE-2024-8746
    35Monitor

    File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload

    HighCVSS 8.8No exploitEPSS 1%

    filemanagerpro · file managerOct 16, 2024

  • CVE-2024-8507
    35Monitor

    File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload

    HighCVSS 8.8No exploitEPSS 0%

    filemanagerpro · file managerOct 16, 2024

  • CVE-2024-0761
    30Monitor

    File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames

    HighCVSS 7.5No exploitEPSS 1%

    filemanagerpro · file managerFeb 5, 2024

  • CVE-2024-2654
    27Monitor

    File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal

    MediumCVSS 6.8No exploitEPSS 1%

    filemanagerpro · file managerApr 9, 2024

  • There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parame

    MediumCVSS 6.1No exploitEPSS 1%

    filemanagerpro · file managerApr 15, 2019

  • The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request

    MediumCVSS 5.4Proof of conceptEPSS 1%

    filemanagerpro · file managerSep 7, 2018

  • WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 1%

    filemanagerpro · file managerApr 5, 2021

  • CVE-2024-8918
    21Monitor

    File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload

    MediumCVSS 5.4No exploitEPSS 0%

    filemanagerpro · file managerOct 16, 2024