Shared Files
Shared Files: vulnerabilidades y CVE
Shared Files tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12514 | Media (5.3) | 0.22% | — | 28 ago 2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and… |
| CVE-2026-12513 | Media (6.8) | 0.33% | — | 28 ago 2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is… |
| CVE-2026-78269 | Media (6.4) | 0.23% | — | 24 ago 2026 | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. |
| CVE-2026-49112 | Alta (7.5) | 0.50% | — | 15 jun 2026 | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. |
| CVE-2025-15433 | Media (6.8) | 0.43% | — | 26 mar 2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector |
| CVE-2025-4392 | Alta (7.2) | 0.36% | — | 3 jun 2025 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient… |