filemanagerpro records
14 published records for vendor filemanagerpro.
Researcher profile
- Entered KEV
- 1 · 7.1%
- Weaponized
- 1 · 7.1%
- Pre-auth RCE
- 4
- With a fix record
- 7.1%
- Median publish → KEV
- 420 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization1
- CWE-330 Use of Insufficiently Random Values1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
98Now | CVE-2020-25213Weaponized | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because filemanagerpro · file manager · CWE-434 | Critical9.8 | KEV | 97.3% | Sep 9, 2020 |
40Plan | CVE-2023-6846No exploit | File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Uploadfilemanagerpro · file manager · CWE-94 | High8.8 | — | 15.9% | Feb 5, 2024 |
39Monitor | CVE-2018-25105No exploit | File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Downloadfilemanagerpro · file manager · CWE-862 | Critical9.8 | — | 0.8% | Oct 16, 2024 |
38Monitor | CVE-2024-1538No exploit | File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusionfilemanagerpro · file manager · CWE-352 | High8.8 | — | 10.7% | Mar 21, 2024 |
35Monitor | CVE-2020-24312Proof of concept | mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file.filemanagerpro · file manager · CWE-552 | High7.5 | — | 15.9% | Aug 26, 2020 |
35Monitor | CVE-2018-16966No exploit | There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path paramefilemanagerpro · file manager · CWE-352 | High8.8 | — | 0.9% | Apr 15, 2019 |
35Monitor | CVE-2024-8746No exploit | File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Uploadfilemanagerpro · file manager · CWE-434 | High8.8 | — | 0.6% | Oct 16, 2024 |
35Monitor | CVE-2024-8507No exploit | File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Uploadfilemanagerpro · file manager · CWE-352 | High8.8 | — | 0.3% | Oct 16, 2024 |
30Monitor | CVE-2024-0761No exploit | File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenamesfilemanagerpro · file manager · CWE-330 | High7.5 | — | 1.0% | Feb 5, 2024 |
27Monitor | CVE-2024-2654No exploit | File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversalfilemanagerpro · file manager · CWE-35 | Medium6.8 | — | 0.9% | Apr 9, 2024 |
24Monitor | CVE-2018-16967No exploit | There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path paramefilemanagerpro · file manager · CWE-79 | Medium6.1 | — | 1.4% | Apr 15, 2019 |
21Monitor | CVE-2018-16363Proof of concept | The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request filemanagerpro · file manager · CWE-79 | Medium5.4 | — | 1.4% | Sep 7, 2018 |
21Monitor | CVE-2021-24177No exploit | WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)filemanagerpro · file manager · CWE-79 | Medium5.4 | — | 0.9% | Apr 5, 2021 |
21Monitor | CVE-2024-8918No exploit | File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Uploadfilemanagerpro · file manager · CWE-434 | Medium5.4 | — | 0.3% | Oct 16, 2024 |
- CVE-2020-2521398Now
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because
CriticalCVSS 9.8KEVWeaponizedEPSS 97%filemanagerpro · file managerSep 9, 2020
- CVE-2023-684640Plan
File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 16%filemanagerpro · file managerFeb 5, 2024
- CVE-2018-2510539Monitor
File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download
CriticalCVSS 9.8No exploitEPSS 1%filemanagerpro · file managerOct 16, 2024
- CVE-2024-153838Monitor
File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion
HighCVSS 8.8No exploitEPSS 11%filemanagerpro · file managerMar 21, 2024
- CVE-2020-2431235Monitor
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file.
HighCVSS 7.5Proof of conceptEPSS 16%filemanagerpro · file managerAug 26, 2020
- CVE-2018-1696635Monitor
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parame
HighCVSS 8.8No exploitEPSS 1%filemanagerpro · file managerApr 15, 2019
- CVE-2024-874635Monitor
File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload
HighCVSS 8.8No exploitEPSS 1%filemanagerpro · file managerOct 16, 2024
- CVE-2024-850735Monitor
File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 0%filemanagerpro · file managerOct 16, 2024
- CVE-2024-076130Monitor
File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames
HighCVSS 7.5No exploitEPSS 1%filemanagerpro · file managerFeb 5, 2024
- CVE-2024-265427Monitor
File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal
MediumCVSS 6.8No exploitEPSS 1%filemanagerpro · file managerApr 9, 2024
- CVE-2018-1696724Monitor
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parame
MediumCVSS 6.1No exploitEPSS 1%filemanagerpro · file managerApr 15, 2019
- CVE-2018-1636321Monitor
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request
MediumCVSS 5.4Proof of conceptEPSS 1%filemanagerpro · file managerSep 7, 2018
- CVE-2021-2417721Monitor
WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 1%filemanagerpro · file managerApr 5, 2021
- CVE-2024-891821Monitor
File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload
MediumCVSS 5.4No exploitEPSS 0%filemanagerpro · file managerOct 16, 2024