Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Frontend File Manager Plugin — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Frontend File Manager Plugin, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the Frontend File Manager Plugin, specifically tracking weaknesses within the Frontend File Manager Plugin family and associated vendor advisories. The collection encompasses various vulnerability classes, including cross-site scripting, arbitrary file upload issues, and privilege escalation flaws, covering historical records from the plugin's initial release through the latest disclosed incidents. Readers can use this resource to monitor a specific vendor's security posture, understand the evolution of a particular weakness class in the frontend domain, and review the complete vulnerability history for this product. The data is organized to facilitate trend analysis and rapid identification of recurring attack vectors, allowing security teams to prioritize remediation efforts based on severity and frequency.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-16292 Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF - - 2026-08-02
CVE-2026-12277 Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal - - 2026-07-07
CVE-2026-8095 Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion CWE-73 8.1 High 2026-06-27
CVE-2026-8380 Frontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion - - 2026-06-26
CVE-2026-8379 Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download - - 2026-06-23
CVE-2026-8378 Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scripting via File Rename - - 2026-06-23
CVE-2026-5337 Frontend File Manager Plugin <= 23.6 - Subscriber+ Arbitrary Download Access via IDOR 6.5 - 2026-05-03
CVE-2026-0829 Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending 6.5AI Medium AI 2026-02-17
CVE-2026-1280 Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter CWE-862 7.5 High 2026-01-28
CVE-2025-14804 Frontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion 6.5 - 2026-01-07
CVE-2025-13382 Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming CWE-639 4.3 Medium 2025-11-25
CVE-2023-7306 Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion CWE-862 7.5 High 2025-07-25
CVE-2023-5105 Frontend File Manager < 22.6 - Editor+ Arbitrary File Download 6.5AI Medium AI 2023-12-04
CVE-2021-4369 Frontend File Manager <= 18.2 - Unauthenticated Content Injection CWE-862 5.8 Medium 2023-06-07
CVE-2021-4368 Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload CWE-862 9.9 Critical 2023-06-07
CVE-2021-4365 Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2023-06-07
CVE-2021-4359 Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion CWE-862 6.5 Medium 2023-06-07
CVE-2021-4356 Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download CWE-862 9.0 Critical 2023-06-07
CVE-2021-4351 Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change CWE-862 5.8 Medium 2023-06-07
CVE-2021-4350 Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails CWE-862 7.2 High 2023-06-07
CVE-2021-4344 Frontend File Manager <= 18.2 - Privilege Escalation CWE-285 6.4 Medium 2023-06-07
CVE-2022-3126 Frontend File Manager < 21.4 - File Upload via CSRF CWE-352 6.5 - 2022-10-17
CVE-2022-3125 Frontend File Manager < 21.3 - Subscriber+ Arbitrary File Upload CWE-434 8.8 - 2022-10-03
CVE-2022-3124 Frontend File Manager < 21.3 - Unauthenticated File Renaming CWE-862 5.3 - 2022-10-03

All 24 known CVE vulnerabilities affecting Frontend File Manager Plugin with full Chinese analysis, references, and POCs where available.