sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total25
Critical3
High15
Medium7
Reset
Showing 21-25 of 25 records
Threat Entry Updated 2026-06-17

File Manager - Security Vulnerability (CVE-2020-24312)

mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.

PLUGIN File Manager

CVE-2020-24312

HIGH CVSS 7.5 2020-08-26
Threat Entry Updated 2026-06-17

File Manager - Cross-Site Scripting (XSS) (CVE-2018-16363)

The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.

PLUGIN File Manager

CVE-2018-16363

MEDIUM CVSS 5.4 2018-09-07
Threat Entry Updated 2026-06-17

File Manager - Security Vulnerability (CVE-2018-7204)

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the wp-config.php file using this plugin, the wp-config.php contents get added to log.txt, which is not protected and contains database credentials, salts, etc. These files have been indexed by Google and a simple dork will find affected sites.

PLUGIN File Manager

CVE-2018-7204

HIGH CVSS 7.5 2018-03-07