Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

File Manager — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in File Manager, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the File Manager product, categorized by vendor, specific software component, and weakness type. It collects all known security flaws reported for this product over the past five years, covering memory corruption, input validation errors, and permission misconfigurations. Readers can use this resource to track a vendor's advisory history, analyze the prevalence of a particular weakness class like buffer overflows, and review the complete vulnerability timeline for the File Manager. The data is structured to support trend analysis and gap identification without relying on individual CVE identifiers. This summary facilitates a holistic view of the security posture for File Manager, enabling users to spot recurring issues, evaluate mitigation effectiveness, and benchmark against broader industry patterns. The aggregation focuses on actionable insights rather than raw entry counts, helping stakeholders prioritize remediation efforts and understand how this product's vulnerability landscape evolves over time.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-85081 Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass - - 2026-09-26
CVE-2026-19708 File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure - - 2026-09-26
CVE-2026-81301 Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access CWE-926 8.5 High 2026-09-14
CVE-2026-17542 Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector - - 2026-08-10
CVE-2026-17541 Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure - - 2026-08-10
CVE-2026-17540 Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch - - 2026-08-10
CVE-2026-15991 File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter CWE-862 8.8 High 2026-08-06
CVE-2025-1725 Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Uploads CWE-434 6.4 Medium 2025-06-03
CVE-2024-37254 WordPress WP File Manager plugin <= 7.2.7 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-11-01
CVE-2018-25105 File Manager <= 3.0 - Unauthenticated Arbitrary File Upload/Download CWE-862 9.8 Critical 2024-10-16
CVE-2024-8743 Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload CWE-434 6.8 Medium 2024-10-05
CVE-2024-7770 Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 8.8 High 2024-09-10
CVE-2024-2654 File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal CWE-35 6.8 Medium 2024-04-09
CVE-2024-1538 File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion CWE-352 8.8 High 2024-03-21
CVE-2023-6825 File Manager And File Manager Pro (Multiple Versions) - Directory Traversal CWE-23 9.9 Critical 2024-03-13
CVE-2024-0761 File Manager <= 7.2.1 - Sensitive Information Exposure via Backup Filenames CWE-330 8.1 High 2024-02-05
CVE-2023-5907 File Manager < 6.3 - Admin+ Arbitrary OS File/Folder Access + Path Traversal 6.5AI Medium AI 2023-12-11
CVE-2021-24177 WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS) CWE-79 5.4 - 2021-04-05

All 18 known CVE vulnerabilities affecting File Manager with full Chinese analysis, references, and POCs where available.