Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Advancedfilemanager

First CVE: Jun 27, 2023Active for: 3 yearsTotal CVEs: 11
51.2
VTI Score
TOP TARGET

Advancedfilemanager develops a file-management application and associated WordPress shortcode plugin that operate in web-facing contexts, where the vendor's vulnerability profile reflects exposure endemic to user-upload and path-handling functionality. The disclosure pattern skews toward serious outcomes and demonstrates a moderate tendency toward public exploit availability, with recurring weaknesses spanning unrestricted file uploads, path traversal, cross-site scripting, authorization flaws, and insecure storage of sensitive data—classes characteristic of file-handling and plugin-based architectures. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Advancedfilemanager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2023
3 years ago
Most Recent CVE
May 7, 2025
443 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2068CRITICAL
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RC
Jun 27, 20239.871NOYES
CVE-2025-47688CRITICAL
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff
May 7, 20259.826NONO
CVE-2024-8126HIGH
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This make
Sep 26, 20248.826NONO
CVE-2023-7061HIGH
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authentica
Jul 10, 20248.826NONO
CVE-2024-11391HIGH
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up
Dec 3, 20247.523NONO
CVE-2024-13333HIGH
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.1
Jan 17, 20257.522NONO
CVE-2024-8704HIGH
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This mak
Sep 26, 20247.222NONO
CVE-2024-5598HIGH
The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function.
Jun 29, 20247.522NONO
CVE-2024-8725MEDIUM
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cann
Sep 26, 20245.418NONO
CVE-2024-13805MEDIUM
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in al
Mar 7, 20255.417NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
55%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High2 (18.2%)
Unknown0 (0.0%)
User Interaction
None9 (81.8%)
Unknown0 (0.0%)
Required2 (18.2%)
Privileges Required
Low6 (54.5%)
High2 (18.2%)
None3 (27.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Advancedfilemanager.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Advancedfilemanager — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Advancedfilemanager's Products

View all 3 CNAs →

Top CWEs