Lucene search

K

Downloadmanager Security Vulnerabilities

cve
cve

CVE-2021-44760

Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6...

5.4CVSS

5.3AI Score

0.001EPSS

2022-03-18 06:15 PM
57
cve
cve

CVE-2022-25606

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url,...

5.4CVSS

5.4AI Score

0.001EPSS

2022-03-25 07:15 PM
76
cve
cve

CVE-2022-25605

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url,...

5.4CVSS

5.4AI Score

0.001EPSS

2022-03-18 06:15 PM
67
cve
cve

CVE-2020-24141

Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute...

5.3CVSS

5.5AI Score

0.001EPSS

2021-07-07 02:15 PM
26
3
cve
cve

CVE-2014-9260

The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress...

8.8CVSS

8.2AI Score

0.014EPSS

2017-08-07 05:29 PM
23