CVEs we hold for Download
Records whose assigning authority named Download as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-57427WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerabilityDownload Monitor - WPForms Lock
CVE-2026-16608Download Monitor < 5.2.6 - Unauthenticated Download Log InjectionUnknown Download Monitor
CVE-2026-14292WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package TitleUnknown Download Manager
CVE-2026-14235WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download KeyUnknown Download Manager
CVE-2025-1286Download HTML TinyMCE Button <= 1.2 - Reflected XSSUnknown Download HTML TinyMCE Button
CVE-2023-6421Download Manager < 3.2.83 - Unauthenticated Protected File Download Password LeakUnknown Download Manager
CVE-2023-1809Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information DisclosureUnknown Download Manager
CVE-2022-2926Download Manager < 3.2.55 - Admin+ Arbitrary File/Folder Access via Path TraversalUnknown Download Manager
CVE-2022-2431Download Manager <= 3.2.50 - Authenticated (Contributor+) Arbitrary File Deletiondownload-manager Download Manager
CVE-2022-2362Download Manager < 3.2.50 - Bypass IP Address Blocking RestrictionUnknown Download Manager
CVE-2022-0828Download Manager < 3.2.39 - Unauthenticated brute force of files master keyUnknown Download Manager
CVE-2021-47940WordPress Download From Files 1.48 Arbitrary File Uploaddownload-from-files Download From Files
CVE-2021-25087Wordpress Download Manager < 3.2.25 - Sensitive Information DisclosureUnknown Download Manager
CVE-2021-25069WordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSSUnknown Download Manager
CVE-2021-24703Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin ActivationUnknown Download Plugin
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.