Known Vulnerabilities for Frontend File Manager by Najeebmedia
Listed below are 3 of the newest known vulnerabilities associated with "Frontend File Manager" by "Najeebmedia".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-64265 json | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly ... | Not Provided | 2025-11-13 | 2026-04-27 |
| CVE-2025-57921 json | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly ... | Not Provided | 2025-09-22 | 2026-04-23 |
| CVE-2025-27358 json | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager ... | Not Provided | 2025-07-04 | 2026-04-23 |
| CVE-2025-13382 json | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... | Not Provided | 2025-11-25 | 2026-04-08 |
| CVE-2024-25903 json | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects ... | Not Provided | 2024-03-17 | 2026-04-28 |
| CVE-2022-3125 json | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a... | 8.8 - HIGH | 2022-10-03 | 2022-10-04 |
| CVE-2022-3124 json | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from u... | 5.3 - MEDIUM | 2022-10-03 | 2022-10-04 |
| CVE-2022-1961 json | The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escapin... | 5.3 - MEDIUM | 2022-06-13 | 2026-04-08 |
| CVE-2022-1707 json | The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter... | 5.3 - MEDIUM | 2022-06-13 | 2026-04-08 |
| CVE-2021-4369 json | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and incl... | 5.3 - MEDIUM | 2023-06-07 | 2026-04-08 |