Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.47% | — | Cminds CM Download Manager | 25/3/2024 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack | |
| Analizada | Media (4.8) | 0.24% | — | Cminds CM Download Manager | 25/3/2024 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack | |
| Analizada | Media (6.8) | 0.22% | — | Cminds CM Download Manager | 25/3/2024 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack | |
| Modificada | Media (5.4) | 0.34% | — | W3eden Download Manager | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84. | |
| Modificada | Media (5.4) | 0.54% | — | W3eden Download Manager | 13/3/2024 | 17/6/2026 | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.3) | 0.55% | — | W3eden Download Manager | 13/3/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published). | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | W3eden Download Manager | 1/1/2024 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. | |
| Modificada | Media (5.4) | 0.65% | — | W3eden Download Manager | 9/6/2023 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.5) | 0.74% | — | W3eden Download Manager | 30/5/2023 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge… | |
| Modificada | Media (5.4) | 0.36% | — | Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager | 3/5/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions. | |
| Modificada | Alta (7.5) | 0.74% | — | W3eden Download Manager | 2/5/2023 | 17/6/2026 | The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files. | |
| Modificada | Media (6.1) | 0.68% | 💥 Exploit | W3eden Download Manager | 18/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. | |
| Modificada | Media (5.4) | 0.57% | — | W3eden Download Manager | 16/1/2023 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | |
| Modificada | Alta (7.2) | 1.5% | — | Cminds CM Download Manager | 26/9/2022 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example. | |
| Modificada | Media (4.9) | 1.7% | — | Adobe Download Manager | 26/9/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory | |
| Modificada | Alta (8.8) | 2.0% | — | W3eden Download Manager | 6/9/2022 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize… | |
| Modificada | Alta (8.8) | 3.8% | — | W3eden Download Manager | 6/9/2022 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it… | |
| Modificada | Alta (8.8) | 0.34% | — | W3eden Download Manager | 23/8/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | |
| Modificada | Media (5.4) | 0.56% | — | W3eden Download Manager | 23/8/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | |
| Modificada | Alta (8.8) | 0.37% | — | W3eden Download Manager | 22/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | |
| Modificada | Alta (7.5) | 1.2% | — | W3eden Download Manager | 22/8/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions. | |
| Modificada | Media (5.4) | 1.1% | — | W3eden Download Manager | 18/7/2022 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above… | |
| Analizada | Media (6.1) | 1.4% | 💥 Exploit | W3eden Download Manager | 17/7/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.65% | — | Wp-filebase Download Manager Project Wp-filebase Download Manager | 24/6/2022 | 17/6/2026 | A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. | |
| Modificada | Media (4.3) | 0.46% | — | W3eden Download Manager | 24/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. |