Vulnerabilities > Advancedfilemanager > Advanced File Manager > 5.2.11

DATE CVE VULNERABILITY TITLE RISK
2025-05-07 CVE-2025-47688 Missing Authorization vulnerability in Advancedfilemanager Advanced File Manager
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
advancedfilemanager CWE-862
critical
9.8
2025-03-07 CVE-2024-13805 Cross-site Scripting vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping.
network
low complexity
advancedfilemanager CWE-79
5.4