Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Simple File List — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Simple File List, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the "Simple File List" product, a component provided by its vendor, focusing on specific weakness types and associated security tags. The collection encompasses a comprehensive range of security flaws, covering the historical time period for which advisory records are available. Readers can use this aggregation to track the vendor's security advisories, analyze the prevalence of particular weakness classes, and review the complete vulnerability history for the product. The data presented here supports systematic analysis of security trends, allowing stakeholders to identify recurring issue patterns and assess the risk landscape for this specific software component.

Vendor: eemitch

CVE ID Title CVSS Severity Published
CVE-2026-16616 Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal - - 2026-08-19
CVE-2026-16617 Simple File List <= 6.3.11 - Unauthenticated Stored XSS via File Description - - 2026-08-19
CVE-2026-57382 WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-13
CVE-2026-12119 Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute CWE-862 6.5 Medium 2026-06-20
CVE-2026-11911 Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter CWE-22 7.5 High 2026-06-20
CVE-2026-11912 Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action CWE-862 7.5 High 2026-06-20
CVE-2026-24953 WordPress Simple File List plugin <= 6.1.15 - Arbitrary File Download vulnerability CWE-22 6.5 Medium 2026-02-20
CVE-2025-68591 WordPress Simple File List plugin <= 6.1.18 - Broken Access Control vulnerability CWE-862 5.4 Medium 2025-12-24
CVE-2025-54021 WordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerability CWE-22 7.5 High 2025-08-20
CVE-2020-36847 Simple File List < 4.2.3 - Remote Code Execution CWE-434 9.8 Critical 2025-07-12
CVE-2025-47450 WordPress Simple File List plugin <= 6.1.13 - Settings Change Vulnerability CWE-862 5.3 Medium 2025-05-07
CVE-2024-10146 Simple File List < 6.1.13 - Reflected Cross-Site Scripting 6.1 - 2024-11-14
CVE-2023-44227 WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion CWE-862 7.5 High 2024-04-17
CVE-2023-39924 WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-10-24
CVE-2023-1025 Simple File List < 6.0.10 - Admin+ Stored XSS 4.8 - 2023-03-27
CVE-2022-3208 Simple File List < 4.4.13 - Page Creation via CSRF CWE-352 6.5 - 2022-10-10
CVE-2022-3207 Simple File List < 4.4.12 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 - 2022-10-10
CVE-2022-3062 Simple File List < 4.4.12 - Reflected Cross-Site Scripting CWE-79 6.1 - 2022-09-26
CVE-2022-1119 Simple File List <= 3.2.7 - Arbitrary File Download CWE-22 7.5 High 2022-04-19

All 19 known CVE vulnerabilities affecting Simple File List with full Chinese analysis, references, and POCs where available.