Simple File List

Explore Simple File List vulnerabilities across all versions. Currently tracking 19 known vulnerabilities, including severity, impact, and patch status.

01234567891023.05.2019Today23.05.20198.6Simple File List <= 3.2.4 - Arbitrary File Deletion CVSS 8.6 · 23.05.20197.5Simple File List <= 3.2.7 - Arbitrary File Download CVSS 7.5 · 23.05.201916.05.20206.5Simple File List <= 4.2.7 - Arbitrary File Deletion CVSS 6.5 · 16.05.202002.11.20209.8Simple File List < 4.2.3 - Remote Code Execution CVSS 9.8 · 02.11.202026.08.20226.1Simple File List <= 4.4.11 - Reflected Cross-Site Scripting CVSS 6.1 · 26.08.202219.09.20226.1Simple File List <= 4.4.11 - Reflected Cross-Site Scripting CVSS 6.1 · 19.09.20228.8Simple File List <= 4.4.12 - Cross-Site Request Forgery to Page Creation CVSS 8.8 · 19.09.202228.02.20234.4Simple File List <= 6.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.02.202328.09.20239.1Simple File List <= 6.1.9 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 28.09.202312.10.20234.4Simple File List <= 6.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings CVSS 4.4 · 12.10.202324.10.20246.1Simple File List <= 6.1.11 - Reflected Cross-Site Scripting CVSS 6.1 · 24.10.202407.05.20255.3Simple File List <= 6.1.13 - Missing Authorization to Unauthenticated Minor Settings Update CVSS 5.3 · 07.05.202528.07.20255.3Simple File List <= 6.1.14 - Unauthenticated Arbitrary File Download CVSS 5.3 · 28.07.202525.12.20254.3Simple File List <= 6.3.7 - Missing Authorization CVSS 4.3 · 25.12.202509.02.20266.5Simple File List <= 6.1.15 - Authenticated (Subscriber+) Arbitrary File Download CVSS 6.5 · 09.02.202619.06.20266.5Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute CVSS 6.5 · 19.06.20267.5Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter CVSS 7.5 · 19.06.20267.5Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action CVSS 7.5 · 19.06.202607.07.20266.1Simple File List <= 6.3.8 - Reflected Cross-Site Scripting CVSS 6.1 · 07.07.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage100%
Open

0

Fixed

19

Get automatic notifications for all Simple File List vulnerabilities before they are exploited.

Vulnerability Records

19 records
2026-07-07 00:00CVE-2026-57382
6.1
Medium
Nguyen Ba KhanhYes
2026-06-19 20:27CVE-2026-12119
6.5
Medium
Chloe ChamberlandYes
2026-06-19 20:27CVE-2026-11911
7.5
High
Chloe ChamberlandYes
2026-06-19 20:27CVE-2026-11912
7.5
High
Chloe ChamberlandYes
2026-02-09 00:00CVE-2026-24953
6.5
Medium
darooYes
2025-12-25 00:00CVE-2025-68591
4.3
Medium
darooYes
2025-07-28 00:00CVE-2025-54021
5.3
Medium
Phat RiOYes
2025-05-07 00:00CVE-2025-47450
5.3
Medium
Kévin Mosbahi (Mika)Yes
2024-10-24 00:00CVE-2024-10146
6.1
Medium
tu3n4nhYes
2023-10-12 00:00CVE-2023-39924
4.4
Medium
Song Hyun BaeYes
Showing 1–10 of 19 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C