CVE Tools

Filemanagerpro

4 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.

Filemanagerpro CVEs per month

Oct 2024 to Oct 2024. Point at a month, or focus the strip and use the arrow keys.
Filemanagerpro CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1040

Products

The products that kept showing up in Filemanagerpro's monthly top three, with their CVEs summed over those months.

  1. File Manager41 month

Latest CVEs

The 14 most recently published vulnerabilities affecting Filemanagerpro.

  1. CVE-2024-8507File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload8.8
  2. CVE-2018-25105File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download9.8
  3. CVE-2024-8746File Manager Pro <= 8.3.9 - Unauthenticated Backup File Download and Upload7.5
  4. CVE-2024-8918File Manager Pro <= 8.3.9 - Unauthenticated Limited JavaScript File Upload7.4
  5. CVE-2024-2654File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal6.8
  6. CVE-2024-1538File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion8.8
  7. CVE-2023-6846File Manager Pro <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Upload8.8
  8. CVE-2024-0761File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames8.1
  9. CVE-2021-24177WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)5.4
  10. CVE-2020-25213The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to h...10.0
  11. CVE-2020-24312mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and ...7.5
  12. CVE-2018-16967There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.6.1
  13. CVE-2018-16966There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.8.8
  14. CVE-2018-16363The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php ...5.4

The record

Peak rank
#183 in Oct 2024
Busiest month shown
Oct 2024, 4 CVEs
Months with a KEV entry
0 since Oct 2024
Monthly snapshots
1 since 2024
Filemanagerpro's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store