Known vulnerabilities in the File Manager plugin
28 security advisories have been published for the File Manager plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- File Manager - Denial of Service (CVE-2026-17540) HIGH
- File Manager - Broken Access Control (CVE-2026-17542) HIGH
- File Manager - Security Vulnerability (CVE-2026-17541) HIGH
- File Manager - Remote Code Execution (CVE-2026-15991) HIGH
- File Manager - Security Vulnerability (CVE-2026-6382) CRITICAL
- File Manager - Security Vulnerability (CVE-2025-12640) MEDIUM
- File Manager - Broken Access Control (CVE-2025-12900) MEDIUM
- File Manager - Security Vulnerability (CVE-2025-12971) MEDIUM
- File Manager - Broken Access Control (CVE-2025-11510) MEDIUM
- File Manager - SQL Injection (CVE-2025-6986) MEDIUM
- File Manager - Cross-Site Scripting (XSS) (CVE-2025-1725) MEDIUM
- File Manager - Cross-Site Request Forgery (CSRF) (CVE-2024-8507) HIGH
- File Manager - Remote Code Execution (CVE-2024-8746) HIGH
- File Manager - Arbitrary File Upload (CVE-2024-8918) HIGH
- File Manager - Remote Code Execution (CVE-2024-7770) HIGH
- File Manager - Remote Code Execution (CVE-2024-7627) HIGH
- File Manager - Cross-Site Scripting (XSS) (CVE-2024-7317) MEDIUM
- File Manager - Cross-Site Scripting (XSS) (CVE-2024-2345) MEDIUM
- File Manager - Cross-Site Scripting (XSS) (CVE-2024-2328) MEDIUM
- File Manager - Security Vulnerability (CVE-2024-2346) MEDIUM
- File Manager - Path Traversal (CVE-2024-2654) MEDIUM
- File Manager - Cross-Site Scripting (XSS) (CVE-2024-2027) MEDIUM
- File Manager - Remote Code Execution (CVE-2024-1538) HIGH
- File Manager - Path Traversal (CVE-2023-6825) CRITICAL
- File Manager - Information Disclosure (CVE-2024-0761) HIGH
- File Manager - Arbitrary File Upload (CVE-2023-6846) HIGH
- File Manager - Security Vulnerability (CVE-2023-5907) MEDIUM
- File Manager - Cross-Site Scripting (XSS) (CVE-2021-24177) MEDIUM