Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

File Manager — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in File Manager, with AI-generated Chinese analysis, references, and POCs.

This page details aggregate vulnerability data for the File Manager product, focusing on common weakness classifications and security tags within the file management software category. It compiles a comprehensive collection of security flaws, including remote code execution, privilege escalation, path traversal, and information disclosure issues. The dataset covers reported vulnerabilities from the last five years, ensuring a robust historical perspective on security trends and patching efficacy in this domain. Here, you can track a vendor's advisories over time to understand their response patterns and transparency regarding security incidents. You can also delve into specific weakness classes to grasp the underlying technical mechanisms and common exploitation techniques associated with file manipulation errors. Furthermore, this resource allows you to look up a product's vulnerability history, providing context on how security issues have evolved and been mitigated across different versions. This aggregation serves as a central reference for security researchers, developers, and IT administrators who need to assess risk, prioritize patching efforts, and compare security postures among various file management solutions. By analyzing these aggregated insights, stakeholders can make informed decisions about software procurement, configuration hardening, and ongoing maintenance strategies. The goal is to provide a clear, factual overview of the security landscape for File Manager applications, facilitating better understanding and management of potential threats.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-17541 Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure --2026-08-10
CVE-2026-17542 Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector --2026-08-10
CVE-2026-17540 Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch --2026-08-10
CVE-2026-15991 File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter CWE-862 8.8 High2026-08-06
CVE-2025-1725 Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Uploads CWE-434 6.4 Medium2025-06-03
CVE-2024-37254 WordPress WP File Manager plugin <= 7.2.7 - Broken Access Control vulnerability CWE-862 4.3 Medium2024-11-01
CVE-2018-25105 File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download CWE-862 9.8 Critical2024-10-16
CVE-2024-8743 Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload CWE-434 6.8 Medium2024-10-05
CVE-2024-7770 Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High2024-09-10
CVE-2024-2654 File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal CWE-35 6.8 Medium2024-04-09
CVE-2024-1538 File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion CWE-352 8.8 High2024-03-21
CVE-2023-6825 File Manager And File Manager Pro (Multiple Versions) - Directory Traversal CWE-23 9.9 Critical2024-03-13
CVE-2024-0761 File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames CWE-330 8.1 High2024-02-05
CVE-2023-5907 File Manager < 6.3 - Admin+ Arbitrary OS File/Folder Access + Path Traversal 6.5AIMediumAI2023-12-11
CVE-2021-24177 WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS) CWE-79 5.4 -2021-04-05

All 15 known CVE vulnerabilities affecting File Manager with full Chinese analysis, references, and POCs where available.