threat
engine
.sh
Back
·
··:··
Home
/
Product
/
w3eden download manager
Product
w3eden download manager
63 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-4367
< 3.3.19
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortc
6.4
MEDIUM
CVE-2024-8284
< 3.2.99
The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high priv
4.8
MEDIUM
CVE-2024-13126
< 3.3.07
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allo
4.6
MEDIUM
CVE-2025-1785
< 3.3.09
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via th
5.4
MEDIUM
CVE-2024-56217
< 3.3.04
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access
4.3
MEDIUM
CVE-2024-10706
< 3.3.03
The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high priv
4.8
MEDIUM
CVE-2024-11768
< 3.3.04
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper pas
5.3
MEDIUM
CVE-2024-11740
< 3.3.04
The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,
7.3
HIGH
CVE-2024-8444
< 3.3.00
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scri
5.4
MEDIUM
CVE-2024-6208
< 3.2.98
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortc
6.4
MEDIUM
CVE-2024-2098
< 3.2.90
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on t
7.5
HIGH
CVE-2024-1766
< 3.2.87
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions u
4.4
MEDIUM
CVE-2024-5266
< 3.2.94
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package,
6.4
MEDIUM
CVE-2024-4001
< 3.2.94
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' sh
6.4
MEDIUM
CVE-2024-4160
< 3.2.90
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortc
6.4
MEDIUM
CVE-2024-32131
< 3.2.83
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Byp
5.3
MEDIUM
CVE-2024-29114
< 3.2.85
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manag
6.5
MEDIUM
CVE-2023-6954
<= 3.2.85
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all ve
6.4
MEDIUM
CVE-2023-6785
< 3.2.85
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all version
5.3
MEDIUM
CVE-2023-6421
< 3.2.83
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an inval
7.5
HIGH
CVE-2023-2305
< 3.2.71
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form',
6.4
MEDIUM
CVE-2023-1524
< 3.2.71
The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon vali
6.5
MEDIUM
CVE-2023-1809
>= 6.0.0 and < 6.3.0
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attacker
7.5
HIGH
CVE-2022-45836
< 3.2.60
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
6.3
MEDIUM
CVE-2022-4476
< 3.2.62
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputti
5.4
MEDIUM
CVE-2022-2926
< 3.2.55
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users
4.9
MEDIUM
CVE-2022-2436
< 3.2.50
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' paramete
8.8
HIGH
CVE-2022-2431
<= 3.2.50
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This i
8.1
HIGH
CVE-2022-36288
<= 3.2.48
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
5.4
MEDIUM
CVE-2022-34658
<= 3.2.48
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <=
5.4
MEDIUM
CVE-2022-34347
<= 3.2.48
Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
4.2
MEDIUM
CVE-2022-2362
< 3.2.50
The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE
7.5
HIGH
CVE-2022-2101
<= 3.2.46
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
file[files][]
parameter in versio
6.4
MEDIUM
CVE-2022-2168
< 3.2.44
The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of t
6.1
MEDIUM
CVE-2017-20093
all versions
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function
4.3
MEDIUM
CVE-2022-1985
<= 3.2.42
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42.
6.1
MEDIUM
CVE-2022-0828
< 3.2.34
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowi
7.5
HIGH
CVE-2021-25087
< 3.2.35
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allo
7.5
HIGH
CVE-2021-25069
< 3.2.34
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQ
8.8
HIGH
CVE-2021-24969
< 3.2.22
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in v
5.4
MEDIUM
CVE-2021-24773
< 3.2.16
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them,
4.8
MEDIUM
CVE-2021-34639
<= 3.1.24
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a doub
7.5
HIGH
CVE-2021-34638
<= 3.1.24
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sens
6.5
MEDIUM
CVE-2020-9688
all versions
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary c
7.8
HIGH
CVE-2019-8071
all versions
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to p
9.8
CRITICAL
CVE-2019-15889
< 2.9.94
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby
6.1
MEDIUM
CVE-2017-18032
< 2.9.52
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admi
6.1
MEDIUM
CVE-2014-9260
< 2.7.3
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update
8.8
HIGH
CVE-2017-2217
<= 2.9.50
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arb
6.1
MEDIUM
CVE-2017-2216
<= 2.9.49
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitra
6.1
MEDIUM
CVE-2017-3823
all versions
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container befor
8.8
HIGH
CVE-2016-3685
<= 2.1.142
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allo
4.7
MEDIUM
CVE-2016-3684
<= 2.1.142
SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent at
4.7
MEDIUM
CVE-2014-8585
all versions
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary
CVE-2013-7319
<= 2.5.8
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inje
CVE-2012-0980
all versions
SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via
CVE-2010-0189
<= 1.6.2.60
A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download
CVE-2009-2582
<= 2.2.4.3
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web serv
CVE-2008-1770
<= 2.2.3.5
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the downlo
CVE-2007-6339
<= 2.2.0.0
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers
CVE-2007-1892
all versions
Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows
CVE-2007-1891
all versions
Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (Dow
CVE-2006-5856
<= 2.1
Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin