Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.22% | — | File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the… | |
| Aplazada | Alta (8.5) | 0.32% | — | Advancedfilemanager Advanced File ManagerAI | 19/8/2026 | 26/8/2026 | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive… | |
| Aplazada | Media (6.1) | 0.39% | — | Advancedfilemanager Advanced File ManagerAI | 16/8/2026 | 20/8/2026 | The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (5.5) | 0.50% | — | ResponsivefilemanagerAI | 4/8/2026 | 12/8/2026 | A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for… | |
| Aplazada | Crítica (9.1) | 1.4% | — | FileorganizerAIFile ManagerAIAdvancedfilemanager Advanced File ManagerAIFilemanagerpro File Manager PROAI | 6/7/2026 | 6/7/2026 | The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Alexantr FilemanagerAI | 29/6/2026 | 30/6/2026 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component | |
| Aplazada | Crítica (9.3) | 0.71% | — | Responsivefilemanager Responsive FilemanagerAI | 15/6/2026 | 17/6/2026 | Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0 | |
| Aplazada | Alta (8) | 0.61% | — | Responsivefilemanager Responsive File ManagerAI | 28/5/2026 | 17/6/2026 | An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component | |
| Aplazada | Baja (2.1) | 0.35% | — | Prasathmani TinyfilemanagerAI | 17/4/2026 | 17/6/2026 | A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulation of the argument uploadurl causes server-side request forgery. It is possible… | |
| Aplazada | Baja (2.1) | 0.54% | — | Prasathmani TinyfilemanagerAI | 17/4/2026 | 17/6/2026 | A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack may be performed from remote. The exploit has been made public and… | |
| Analizada | Media (6.9) | 0.56% | — | Dulldusk Phpfilemanager | 24/3/2026 | 17/6/2026 | phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd… | |
| Analizada | Crítica (9.8) | 0.64% | — | Livewire-filemanager Filemanager | 16/1/2026 | 17/6/2026 | Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel… | |
| Analizada | Crítica (9.3) | 0.62% | — | Dulldusk Phpfilemanager | 16/12/2025 | 17/6/2026 | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server. | |
| Rechazada | Sin puntuar | — | — | Unisharp Laravel-filemanagerAI | 5/9/2025 | 5/9/2025 | Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager. | |
| Analizada | Media (6.5) | 0.47% | — | Simogeo Filemanager | 18/7/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
| Analizada | Media (6.5) | 1.7% | — | Simogeo Filemanager | 18/7/2025 | 17/6/2026 | An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint. | |
| Analizada | Crítica (9.8) | 0.67% | — | Simogeo Filemanager | 18/7/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Aplazada | Alta (7.2) | 0.62% | — | Filemanagerpro.io File Manager PROAI | 14/6/2025 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's… | |
| Aplazada | Alta (7.2) | 0.83% | — | Advanced File Manager PRO PremiumAIAdvancedfilemanager File Manager Advanced ShortcodeAI | 15/5/2025 | 17/6/2026 | The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' shortcode. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.35% | — | Advancedfilemanager Advanced File Manager | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1. | |
| Analizada | Media (5.4) | 0.27% | — | Advancedfilemanager Advanced File Manager | 7/3/2025 | 17/6/2026 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.90% | — | Advancedfilemanager Advanced File Manager | 17/1/2025 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by… | |
| Aplazada | Media (6.1) | 0.30% | — | Tecrail Responsive FilemanagerAI | 10/1/2025 | 17/6/2026 | Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions. | |
| Aplazada | Alta (8.9) | 1.3% | — | Unisharp Laravel-filemanagerAI | 18/12/2024 | 17/6/2026 | Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code. | |
| Analizada | Alta (7.5) | 0.70% | — | Advancedfilemanager Advanced File Manager | 3/12/2024 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted… |