N-Media Frontend File Manager vulnerabilities

5 known vulnerabilities affecting n-media/frontend_file_manager.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2UNKNOWN2

Vulnerabilities

Page 1 of 1
CVE-2026-25005MEDIUMCVSS 5.3≤ 23.52026-02-19
CVE-2026-25005 [MEDIUM] CWE-639 CVE-2026-25005: Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmed Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.
cvelistv5nvd
CVE-2025-64265MEDIUMCVSS 4.3≤ 23.22025-11-13
CVE-2025-64265 [MEDIUM] CWE-862 CVE-2025-64265: Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allow Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2.
cvelistv5nvd
CVE-2025-57921UNKNOWN≤ 23.32025-09-22
CVE-2025-57921 CWE-862 CVE-2025-57921: Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allow Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.3.
cvelistv5nvd
CVE-2025-27358UNKNOWN≤ 23.62025-07-04
CVE-2025-27358 CWE-80 CVE-2025-27358: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Med Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Code Injection.This issue affects Frontend File Manager: from n/a through <= 23.6.
cvelistv5nvd
CVE-2024-25903HIGHCVSS 7.5≥ n/a, ≤ 22.72024-03-17
CVE-2024-25903 [HIGH] CWE-200 CVE-2024-25903: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Ma Exposure of Sensitive Information to an Unauthorized Actor vulnerability in N-Media Frontend File Manager.This issue affects Frontend File Manager: from n/a through 22.7.
cvelistv5nvd