Simple File List

Simple File List has 21 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2026; 19 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 7 high. 2026 was the busiest year with 7 disclosures.

The most common weakness is Path Traversal, behind 8 of the records (38%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

19 of the records (90%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.

16 independent researchers contributed these findings, most of them (3) reported by Chloe Chamberland.

01234567891023.05.2019Today23.05.20198.6Simple File List <= 3.2.4 - Arbitrary File Deletion CVSS 8.6 · 23.05.20197.5Simple File List <= 3.2.7 - Arbitrary File Download CVSS 7.5 · 23.05.201916.05.20206.5Simple File List <= 4.2.7 - Arbitrary File Deletion CVSS 6.5 · 16.05.202002.11.20209.8Simple File List < 4.2.3 - Remote Code Execution CVSS 9.8 · 02.11.202026.08.20226.1Simple File List <= 4.4.11 - Reflected Cross-Site Scripting CVSS 6.1 · 26.08.202219.09.20226.1Simple File List <= 4.4.11 - Reflected Cross-Site Scripting CVSS 6.1 · 19.09.20228.8Simple File List <= 4.4.12 - Cross-Site Request Forgery to Page Creation CVSS 8.8 · 19.09.202228.02.20234.4Simple File List <= 6.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 28.02.202328.09.20239.1Simple File List <= 6.1.9 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 28.09.202312.10.20234.4Simple File List <= 6.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings CVSS 4.4 · 12.10.202324.10.20246.1Simple File List <= 6.1.11 - Reflected Cross-Site Scripting CVSS 6.1 · 24.10.202407.05.20255.3Simple File List <= 6.1.13 - Missing Authorization to Unauthenticated Minor Settings Update CVSS 5.3 · 07.05.202528.07.20255.3Simple File List <= 6.1.14 - Unauthenticated Arbitrary File Download CVSS 5.3 · 28.07.202525.12.20254.3Simple File List <= 6.3.7 - Missing Authorization CVSS 4.3 · 25.12.202509.02.20266.5Simple File List <= 6.1.15 - Authenticated (Subscriber+) Arbitrary File Download CVSS 6.5 · 09.02.202619.06.20266.5Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute CVSS 6.5 · 19.06.20267.5Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter CVSS 7.5 · 19.06.20267.5Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action CVSS 7.5 · 19.06.202607.07.20266.1Simple File List <= 6.3.8 - Reflected Cross-Site Scripting CVSS 6.1 · 07.07.202621.08.20267.2Simple File List <= 6.3.11 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 21.08.20267.5Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read CVSS 7.5 · 21.08.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage90%
Open

2

Fixed

19

Get automatic notifications for all Simple File List vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2026-16616

Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read

Read the full analysis

Vulnerability Records

21 records
2026-08-21 00:00CVE-2026-16617
7.2
High
Ruwantha HarshamalNo
2026-08-21 00:00CVE-2026-16616
7.5
High
Sanjar TulkinovNo
2026-07-07 00:00CVE-2026-57382
6.1
Medium
Nguyen Ba KhanhYes
2026-06-19 20:27CVE-2026-12119
6.5
Medium
Chloe ChamberlandYes
2026-06-19 20:27CVE-2026-11911
7.5
High
Chloe ChamberlandYes
2026-06-19 20:27CVE-2026-11912
7.5
High
Chloe ChamberlandYes
2026-02-09 00:00CVE-2026-24953
6.5
Medium
darooYes
2025-12-25 00:00CVE-2025-68591
4.3
Medium
darooYes
2025-07-28 00:00CVE-2025-54021
5.3
Medium
Phat RiOYes
2025-05-07 00:00CVE-2025-47450
5.3
Medium
Kévin Mosbahi (Mika)Yes
Showing 1–10 of 21 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C