| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-13293 | POST File - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2024-059 | Drupal | POST File | 中危 | - | 2025-01-09 20:17:22 | Deep Dive |
| CVE-2024-13276 | File Entity (fieldable files) - Moderately critical - Information Disclosure - SA-CONTRIB-2024-040 | Drupal | File Entity (fieldable files) | 中危 | - | 2025-01-09 19:28:41 | Deep Dive |
| CVE-2024-13237 | File Entity (fieldable files) - Moderately critical - Cross Site Scripting, Access bypass - SA-CONTRIB-2024-001 | Drupal | File Entity (fieldable files) | 中危 | - | 2025-01-09 18:15:24 | Deep Dive |
| CVE-2024-9939 | WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php | nickboss | Iptanus File Upload | High | 7.5 | 2025-01-08 08:18:17 | Deep Dive |
| CVE-2024-11635 | WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution | nickboss | Iptanus File Upload | Critical | 9.8 | 2025-01-08 07:18:39 | Deep Dive |
| CVE-2024-11613 | WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion | nickboss | Iptanus File Upload | Critical | 9.8 | 2025-01-08 06:41:36 | Deep Dive |
| CVE-2024-12719 | WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal | nickboss | Iptanus File Upload | Medium | 4.3 | 2025-01-07 09:22:15 | Deep Dive |
| CVE-2024-12701 | WP Smart Import : Import any XML File to WordPress <= 1.1.2 - Reflected Cross-Site Scripting | xylus | WP Smart Import : Import any XML File to WordPress | Medium | 6.1 | 2025-01-04 07:24:23 | Deep Dive |
| CVE-2024-12331 | File Manager Pro – Filester <= 1.8.6 - Missing Authorization to Authenticated (Subscriber+) Filebird Plugin Installation | ninjateam | File Manager Pro – Filester | Medium | 4.3 | 2024-12-19 11:14:15 | Deep Dive |
| CVE-2024-11391 | Advanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File Upload | saadiqbal | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | High | 7.5 | 2024-12-03 14:34:30 | Deep Dive |
| CVE-2024-9669 | File Manager Pro – Filester <= 1.8.5 - Authenticated (Administrator+) Local JavaScript File Inclusion | ninjateam | File Manager Pro – Filester | High | 7.2 | 2024-11-28 08:47:32 | Deep Dive |
| CVE-2024-8066 | File Manager Pro – Filester <= 1.8.6- Authenticated (Subscriber+) Arbitrary File Upload | ninjateam | File Manager Pro – Filester | High | 7.5 | 2024-11-28 08:47:31 | Deep Dive |
| CVE-2024-11265 | Wp Maximum Upload File Size <= 1.1.3 - Authenticated (Author+) Full Path Disclosure | codepopular | EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time | Medium | 4.3 | 2024-11-23 05:40:12 | Deep Dive |
| CVE-2024-10482 | Media Library Tools < 1.5.0 - Author+ Stored XSS via SVG | Unknown | Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO | 中危 | - | 2024-11-21 06:00:02 | Deep Dive |
| CVE-2024-51841 | WordPress File Select Control For Elementor plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | Abdul Awal Uzzal | File Select Control For Elementor | Medium | 6.5 | 2024-11-19 16:31:39 | Deep Dive |
| CVE-2024-51892 | WordPress Sell Media File with Stripe plugin <= 1.0.6 - Stored Cross Site Scripting (XSS) vulnerability | Noor Alam | Sell Media File with Stripe | Medium | 6.5 | 2024-11-19 16:31:13 | Deep Dive |
| CVE-2024-10146 | Simple File List < 6.1.13 - Reflected Cross-Site Scripting | Unknown | Simple File List | 中危 | - | 2024-11-14 06:00:07 | Deep Dive |
| CVE-2024-49256 | WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerability | WP Chill | Htaccess File Editor | Medium | 5.4 | 2024-11-01 14:18:46 | Deep Dive |
| CVE-2024-37254 | WordPress WP File Manager plugin <= 7.2.7 - Broken Access Control vulnerability | mndpsingh287 | File Manager | Medium | 4.3 | 2024-11-01 14:18:29 | Deep Dive |
| CVE-2024-39639 | WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability | Nickolas Bossinas | WordPress File Upload | Medium | 4.3 | 2024-11-01 14:17:54 | Deep Dive |