Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High2
Medium3
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2025-06-04

CVE-2025-4392 - Shared Files Plugin

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible for unauthenticated attackers to bypass the plugin’s MIME-only checks and inject arbitrary web scripts in pages that will execute whenever a user accesses the html file.

PLUGIN Shared Files

CVE-2025-4392

HIGH CVSS 7.2 2025-06-03
Threat Entry Updated 2025-01-31

CVE-2024-13504 - Shared Files Plugin

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the dfxp file. This issue affects only Apache-based environments, where dfxp files are handled by default.

PLUGIN Shared Files

CVE-2024-13504

HIGH CVSS 7.2 2025-01-31
Threat Entry Updated 2025-04-23

CVE-2023-4819 - Shared Files Plugin

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

PLUGIN Shared Files

CVE-2023-4819

MEDIUM CVSS 6.1 2023-10-16
Threat Entry Updated 2024-11-21

CVE-2021-24856 - Shared Files Plugin

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

PLUGIN Shared Files

CVE-2021-24856

MEDIUM CVSS 4.8 2021-11-17
Threat Entry Updated 2024-11-21

CVE-2021-24736 - Shared Files Plugin

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

PLUGIN Shared Files

CVE-2021-24736

MEDIUM CVSS 4.8 2021-10-18
Scroll to top