W3 Eden Inc Download Manager vulnerabilities

6 known vulnerabilities affecting w3_eden_inc/download_manager.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-32131HIGHCVSS 7.5≥ n/a, ≤ 3.2.822024-05-17
CVE-2024-32131 [HIGH] CWE-200 CVE-2024-32131: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Ma Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.
cvelistv5nvd
CVE-2024-29114MEDIUMCVSS 5.4≥ n/a, ≤ 3.2.842024-03-19
CVE-2024-29114 [MEDIUM] CWE-79 CVE-2024-29114: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.
cvelistv5nvd
CVE-2022-45836MEDIUMCVSS 6.1PoC≥ n/a, ≤ 3.2.592023-04-18
CVE-2022-45836 [MEDIUM] CWE-79 CVE-2022-45836: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
cvelistv5nvd
CVE-2022-36288HIGHCVSS 8.8≤ 3.2.482022-08-23
CVE-2022-36288 [HIGH] CWE-352 CVE-2022-36288: Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2 Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
cvelistv5nvd
CVE-2022-34658MEDIUMCVSS 5.4≤ 3.2.482022-08-23
CVE-2022-34658 [MEDIUM] CWE-79 CVE-2022-34658: Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Ed Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
cvelistv5nvd
CVE-2022-34347HIGHCVSS 8.8≤ 3.2.482022-08-22
CVE-2022-34347 [HIGH] CWE-352 CVE-2022-34347: Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at Word Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
cvelistv5nvd