Vulnerabilities > Advancedfilemanager > Advanced File Manager > 5.2.10

DATE CVE VULNERABILITY TITLE RISK
2025-03-07 CVE-2024-13805 Cross-site Scripting vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping.
network
low complexity
advancedfilemanager CWE-79
5.4