CVE Tools

Codename065

4 CVEs tracked since 2024. Since Jun 2024, none of them reached CISA KEV.

Codename065 CVEs per month

Jun 2024 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Codename065 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0640

Products

The products that kept showing up in Codename065's monthly top three, with their CVEs summed over those months.

  1. Download Manager41 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Codename065.

  1. CVE-2026-93654Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter7.2
  2. CVE-2026-92714Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter6.5
  3. CVE-2026-16685Download Manager <= 3.3.66 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute6.4
  4. CVE-2026-12800Premium Packages <= 6.2.0 - Unauthenticated SQL Injection7.5
  5. CVE-2026-15348Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter6.3
  6. CVE-2026-15906Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter6.5
  7. CVE-2026-14343Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes6.4
  8. CVE-2026-13733Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute6.4
  9. CVE-2026-4057Download Manager <= 3.3.51 - Missing Authorization to Authenticated (Contributor+) Media File Protection Removal4.3
  10. CVE-2026-5357Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes6.4
  11. CVE-2026-2571Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter4.3
  12. CVE-2026-1666Download Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' Parameter6.1
  13. CVE-2025-15364Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword7.3
  14. CVE-2025-13498Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure4.3
  15. CVE-2025-12177Download Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron Key5.3

The record

Peak rank
#172 in Jun 2024
Busiest month shown
Jun 2024, 4 CVEs
Months with a KEV entry
0 since Jun 2024
Monthly snapshots
1 since 2024
Codename065's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store