Vulnerabilities > Ninjateam > Filebird > 4.7.3

DATE CVE VULNERABILITY TITLE RISK
2025-02-25 CVE-2025-26977 Authorization Bypass Through User-Controlled Key vulnerability in Ninjateam Filebird
Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.
network
low complexity
ninjateam CWE-639
7.2
2024-12-09 CVE-2023-25966 Missing Authorization vulnerability in Ninjateam Filebird
Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 5.1.4.
network
low complexity
ninjateam CWE-862
6.5
2024-12-06 CVE-2024-53825 Missing Authorization vulnerability in Ninjateam Filebird
Missing Authorization vulnerability in Ninja Team Filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through 6.3.2.
network
low complexity
ninjateam CWE-862
7.2
2024-05-14 CVE-2024-35166 Unspecified vulnerability in Ninjateam Filebird
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.
network
low complexity
ninjateam
7.5
2024-05-02 CVE-2024-2345 Cross-site Scripting vulnerability in Ninjateam Filebird
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to, and including, 5.6.3 due to insufficient input sanitization and output escaping.
network
low complexity
ninjateam CWE-79
5.4
2024-02-05 CVE-2024-0691 Cross-site Scripting vulnerability in Ninjateam Filebird
The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping.
network
low complexity
ninjateam CWE-79
4.8
2021-07-12 CVE-2021-24385 Unspecified vulnerability in Ninjateam Filebird 4.7.3
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request.
network
low complexity
ninjateam
critical
9.8