Vulnerabilidades em codename065

33 resultados
CVE-2024-4160MEDIUMDownload Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages ShortcodeEPSS 0.3%CVE-2024-1766MEDIUMDownload Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site ScriptingEPSS 0.3%CVE-2024-11768MEDIUMDownload manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protected FilesEPSS 0.3%CVE-2026-5357MEDIUMDownload Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.3%CVE-2025-3056MEDIUMDownload Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2026-1666MEDIUMDownload Manager <= 3.3.46 - Reflected Cross-Site Scripting via 'redirect_to' ParameterEPSS 0.3%CVE-2024-4001MEDIUMDownload Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form ShortcodeEPSS 0.3%CVE-2026-2571MEDIUMDownload Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' ParameterEPSS 0.2%CVE-2025-4367MEDIUMDownload Manager <= 3.3.18 - Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard ShortcodeEPSS 0.2%CVE-2025-10146MEDIUMDownload Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` ParameterEPSS 0.2%CVE-2025-12177MEDIUMDownload Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron KeyEPSS 0.2%CVE-2024-7386MEDIUMPremium Packages – Sell Digital Products Securely <= 5.9.1 - Cross-Site Request ForgeryEPSS 0.2%CVE-2025-15364HIGHDownload Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePasswordEPSS 0.2%