Urbanbase's vulnerability profile is centered on a web-based file distribution product (Z-Downloads) that handles user-uploaded and generated content. The durable signal reflects application-layer input handling, specifically cross-site scripting vulnerabilities that arise in the context of dynamic web page generation. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Urbanbase over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8673CRITICAL The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript. | May 15, 2025 | 9.1 | 35 | NO | YES |
CVE-2024-34555CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3. | May 14, 2024 | 10.0 | 26 | NO | NO |
CVE-2024-8699HIGH The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even w | May 15, 2025 | 7.2 | 21 | NO | NO |
CVE-2024-8703MEDIUM The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform | May 15, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-54206MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads z-downloads allows Stored XSS.This issue affects Z-Down | Dec 6, 2024 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Urbanbase.
Media articles that mention a CVE ID that affects a product developed by Urbanbase — matched by CVE ID, not by vendor name.