Media File Manager Project maintains a focused file-management utility whose vulnerabilities center on web-accessible input handling and directory-access boundaries, reflected in recurring path-traversal and cross-site scripting weaknesses. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Media File Manager Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19040MEDIUM The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-a | Jan 31, 2019 | 5.3 | 33 | NO | YES |
CVE-2018-19043MEDIUM The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mr | Jan 31, 2019 | 5.3 | 32 | NO | YES |
CVE-2018-19042MEDIUM The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to | Jan 31, 2019 | 5.3 | 32 | NO | YES |
CVE-2018-19041MEDIUM The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | Jan 31, 2019 | 6.1 | 30 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Media File Manager Project.
Media articles that mention a CVE ID that affects a product developed by Media File Manager Project — matched by CVE ID, not by vendor name.