simplefilelist records
9 published records for vendor simplefilelist.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 11.1%
- Pre-auth RCE
- 1
- With a fix record
- 22.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2020-36847Weaponized | Simple File List < 4.2.3 - Remote Code Executionsimplefilelist · simple file list · CWE-434 | Critical9.8 | — | 44.2% | Jul 12, 2025 |
41Plan | CVE-2020-12832Proof of concept | WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the applicatiosimplefilelist · simple-file-list · CWE-22 | Critical9.8 | — | 7.1% | May 13, 2020 |
37Monitor | CVE-2022-3062Proof of concept | Simple File List < 4.4.12 - Reflected Cross-Site Scriptingsimplefilelist · simple-file-list · CWE-79 | Medium6.1 | — | 44.1% | Sep 26, 2022 |
36Monitor | CVE-2022-1119Proof of concept | Simple File List <= 3.2.7 - Arbitrary File Downloadsimplefilelist · simple-file-list · CWE-22 | High7.5 | — | 20.0% | Apr 19, 2022 |
26Monitor | CVE-2022-3208No exploit | Simple File List < 4.4.13 - Page Creation via CSRFsimplefilelist · simple-file-list · CWE-352 | Medium6.5 | — | 0.4% | Oct 10, 2022 |
21Monitor | CVE-2024-10146Proof of concept | Simple File List < 6.1.13 - Reflected Cross-Site Scriptingsimplefilelist · simple file list · CWE-79 | Medium5.4 | — | 0.6% | Nov 14, 2024 |
19Monitor | CVE-2022-3207No exploit | Simple File List < 4.4.12 - Admin+ Stored Cross-Site Scriptingsimplefilelist · simple-file-list · CWE-79 | Medium4.8 | — | 0.5% | Oct 10, 2022 |
19Monitor | CVE-2023-1025No exploit | Simple File List < 6.0.10 - Admin+ Stored XSSsimplefilelist · simple file list · CWE-79 | Medium4.8 | — | 0.4% | Mar 27, 2023 |
19Monitor | CVE-2023-39924No exploit | WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Cross Site Scripting (XSS)simplefilelist · simple file list · CWE-79 | Medium4.8 | — | 0.4% | Oct 25, 2023 |
- CVE-2020-3684752Plan
Simple File List < 4.2.3 - Remote Code Execution
CriticalCVSS 9.8WeaponizedEPSS 44%simplefilelist · simple file listJul 12, 2025
- CVE-2020-1283241Plan
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the applicatio
CriticalCVSS 9.8Proof of conceptEPSS 7%simplefilelist · simple-file-listMay 13, 2020
- CVE-2022-306237Monitor
Simple File List < 4.4.12 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 44%simplefilelist · simple-file-listSep 26, 2022
- CVE-2022-111936Monitor
Simple File List <= 3.2.7 - Arbitrary File Download
HighCVSS 7.5Proof of conceptEPSS 20%simplefilelist · simple-file-listApr 19, 2022
- CVE-2022-320826Monitor
Simple File List < 4.4.13 - Page Creation via CSRF
MediumCVSS 6.5No exploitEPSS 0%simplefilelist · simple-file-listOct 10, 2022
- CVE-2024-1014621Monitor
Simple File List < 6.1.13 - Reflected Cross-Site Scripting
MediumCVSS 5.4Proof of conceptEPSS 1%simplefilelist · simple file listNov 14, 2024
- CVE-2022-320719Monitor
Simple File List < 4.4.12 - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%simplefilelist · simple-file-listOct 10, 2022
- CVE-2023-102519Monitor
Simple File List < 6.0.10 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%simplefilelist · simple file listMar 27, 2023
- CVE-2023-3992419Monitor
WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%simplefilelist · simple file listOct 25, 2023