Extension WordPress

Vulnérabilités Simple File List

Cette page rassemble les failles publiées pour Simple File List, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
2Critiques
19Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Simple File List

19 fiches

CVE-2026-12119 Moyenne · 6,5
Simple File List

Simple File List <= 6.3.7 – Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated…

Versions affectées

*-6.3.7

Correctif

6.3.8

Publication

19/06/2026

CVE-2026-11911 Élevée · 7,5
Simple File List

Simple File List <= 6.3.7 – Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers…

Versions affectées

*-6.3.7

Correctif

6.3.8

Publication

19/06/2026

CVE-2026-11912 Élevée · 7,5
Simple File List

Simple File List <= 6.3.7 – Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files…

Versions affectées

*-6.3.7

Correctif

6.3.8

Publication

19/06/2026

CVE-2023-39924 Moyenne · 4,4
Simple File List

Simple File List <= 6.1.9 – Authenticated (Administrator+) Stored Cross-Site Scripting via settings

The Simple File List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-6.1.9

Correctif

6.1.10

Publication

12/10/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités