Tammersoft's vulnerability profile centers on its Shared Files product, a file-sharing and collaboration application where the observed exposure reflects application-layer input-handling deficiencies, specifically cross-site scripting weaknesses in web-facing components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tammersoft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49112HIGH Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. | Jun 15, 2026 | 7.5 | 30 | NO | NO |
CVE-2023-4819MEDIUM The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file exte | Oct 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2021-24856MEDIUM The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Script | Nov 17, 2021 | 4.8 | 18 | NO | NO |
CVE-2021-24736MEDIUM The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some | Oct 18, 2021 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tammersoft.
Media articles that mention a CVE ID that affects a product developed by Tammersoft — matched by CVE ID, not by vendor name.