Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16617— Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description

AI Predicted 6.1 Difficulty: Easy EPSS 0.34% · P27

Possible ATT&CK Techniques 1AI

T1059.007 · JavaScript

Affected Version Matrix 1

VendorProductVersion RangeStatus
UnknownSimple File List≤ 6.3.11affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-16617

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description
Source: CVE Program / CVE List V5
Vulnerability Description
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownSimple File List 0 ~ 6.3.11 -

II. Public POCs for CVE-2026-16617

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16617

登录查看更多情报信息。

Vendor Advisories for CVE-2026-16617 (1)

Same Patch Batch · Unknown · 2026-08-19 · 38 CVEs total

CVE-2026-14826Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration
CVE-2026-18031TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback
CVE-2026-17565Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery
CVE-2026-15253Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title
CVE-2026-16058YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan
CVE-2026-16570NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callba
CVE-2026-16616Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Travers
CVE-2026-14825Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDO
CVE-2026-14334Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SV
CVE-2026-14861User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR
CVE-2026-16979SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key En
CVE-2026-14287TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass
CVE-2026-14196WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update vi
CVE-2026-13174Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR
CVE-2026-13175Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR
CVE-2026-11565Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_
CVE-2026-12983Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
CVE-2026-13169Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeo
CVE-2026-13173Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation
CVE-2026-18777TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Chan

Showing top 20 of 38 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-16617

No comments yet


Leave a comment