Download Manager

70 known CVEs 100K+ active installs

Scan My Site Free

UNKNOWN: 70
Known Vulnerabilities 70
CVE-2026-4057 UNKNOWN EPSS 0.3%
Published 2026-04-10 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all vers
CVE-2026-5357 UNKNOWN EPSS 0.2%
Published 2026-04-09 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to in
CVE-2026-2571 UNKNOWN EPSS 0.1%
Published 2026-03-19 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'reviewUserStatus' function in all versions up to, and including, 3.3.49
CVE-2026-1666 UNKNOWN EPSS 0.2%
Published 2026-02-18 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'redirect_to' parameter in all versions up to, and including, 3.3.46. This is due to insufficient inpu
CVE-2025-15364 UNKNOWN EPSS 0.1%
Published 2026-01-06 · Affected: *
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a u
CVE-2025-13498 UNKNOWN EPSS 0.3%
Published 2025-12-18 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capabilit
CVE-2025-12177 UNKNOWN EPSS 0.1%
Published 2025-11-08 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and in
CVE-2024-56217 UNKNOWN EPSS 0.2%
Published 2024-12-31 · Affected: *
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a
CVE-2024-56217 UNKNOWN EPSS 0.2%
Published 2024-12-31 · Affected: *
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a
CVE-2024-56217 UNKNOWN EPSS 0.2%
Published 2024-12-31 · Affected: *
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a
CVE-2024-56217 UNKNOWN EPSS 0.2%
Published 2024-12-31 · Affected: *
Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a
CVE-2024-2098 UNKNOWN EPSS 0.4%
Published 2024-06-13 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including
CVE-2024-2098 UNKNOWN EPSS 0.4%
Published 2024-06-13 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including
CVE-2024-1766 UNKNOWN EPSS 0.3%
Published 2024-06-12 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and
CVE-2024-1766 UNKNOWN EPSS 0.3%
Published 2024-06-12 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and
CVE-2024-5266 UNKNOWN EPSS 0.3%
Published 2024-06-12 · Affected: *
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all vers
CVE-2024-5266 UNKNOWN EPSS 0.3%
Published 2024-06-12 · Affected: *
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all vers
CVE-2024-4001 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficie
CVE-2024-4001 UNKNOWN EPSS 0.2%
Published 2024-06-05 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficie
CVE-2024-4160 UNKNOWN EPSS 0.3%
Published 2024-05-31 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient i
CVE-2024-4160 UNKNOWN EPSS 0.3%
Published 2024-05-31 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient i
CVE-2023-6954 UNKNOWN EPSS 0.4%
Published 2024-03-13 · Affected: *
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitiza
CVE-2023-6954 UNKNOWN EPSS 0.4%
Published 2024-03-13 · Affected: *
The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitiza
CVE-2023-6785 UNKNOWN EPSS 0.4%
Published 2024-03-13 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthentic
CVE-2023-6785 UNKNOWN EPSS 0.4%
Published 2024-03-13 · Affected: *
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthentic
CVE-2023-2305 UNKNOWN EPSS 0.5%
Published 2023-06-09 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 du
CVE-2023-2305 UNKNOWN EPSS 0.5%
Published 2023-06-09 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdm_members', 'wpdm_login_form', 'wpdm_reg_form' shortcodes in versions up to, and including, 3.2.70 du
CVE-2022-2436 UNKNOWN EPSS 0.7%
Published 2022-09-06 · Affected: *
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for
CVE-2022-2436 UNKNOWN EPSS 0.7%
Published 2022-09-06 · Affected: *
The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for
CVE-2022-2101 UNKNOWN EPSS 0.6%
Published 2022-07-18 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization
CVE-2022-2101 UNKNOWN EPSS 0.6%
Published 2022-07-18 · Affected: *
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization
CVE-2022-1985 UNKNOWN EPSS 0.6%
Published 2022-06-13 · Affected: *
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on
CVE-2022-1985 UNKNOWN EPSS 0.6%
Published 2022-06-13 · Affected: *
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on
CVE-2014-9260 UNKNOWN EPSS 1.0%
Published 2017-08-07 · Affected: *
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
CVE-2017-2217 UNKNOWN EPSS 0.7%
Published 2017-07-07 · Affected: *
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2017-2216 UNKNOWN EPSS 0.7%
Published 2017-07-07 · Affected: *
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-3823 UNKNOWN EPSS 1.0%
Published 2017-02-01 · Affected: <2.1.0.9
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugi
CVE-2010-0189 UNKNOWN EPSS 0.9%
Published 2010-02-23 · Affected: *
A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are n
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.0.4.4
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.0.0
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.1.0
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.3.5
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.3.5
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.1.0
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.3.6
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.0.0
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.2.3.6
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: <2.0.4.4
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: *
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2009-2582 UNKNOWN EPSS 0.9%
Published 2009-07-23 · Affected: *
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a R
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: <2.0.4.4
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: *
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: <2.0.4.4
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: <2.2.0.0
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: <2.2.1.0
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: *
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: <2.2.0.0
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2008-1770 UNKNOWN EPSS 1.0%
Published 2008-06-04 · Affected: <2.2.1.0
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an
CVE-2007-6339 UNKNOWN EPSS 1.0%
Published 2008-05-01 · Affected: *
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified
CVE-2007-6339 UNKNOWN EPSS 1.0%
Published 2008-05-01 · Affected: *
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified
CVE-2007-6339 UNKNOWN EPSS 1.0%
Published 2008-05-01 · Affected: *
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified
CVE-2007-6339 UNKNOWN EPSS 1.0%
Published 2008-05-01 · Affected: *
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified
CVE-2007-1892 UNKNOWN EPSS 0.9%
Published 2007-04-18 · Affected: <2.2.0.0
Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via unspecified vectors, a
CVE-2007-1892 UNKNOWN EPSS 0.9%
Published 2007-04-18 · Affected: <2.2.0.0
Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via unspecified vectors, a
CVE-2007-1891 UNKNOWN EPSS 0.9%
Published 2007-04-18 · Affected: <2.2.0.0
Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote att
CVE-2007-1891 UNKNOWN EPSS 0.9%
Published 2007-04-18 · Affected: <2.2.0.0
Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote att
CVE-2006-5856 UNKNOWN EPSS 1.0%
Published 2006-12-06 · Affected: *
Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long section name in the dm.ini file, which is populated via an AOM file.
CVE-2006-5856 UNKNOWN EPSS 1.0%
Published 2006-12-06 · Affected: *
Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long section name in the dm.ini file, which is populated via an AOM file.
CVE-2006-2964 UNKNOWN EPSS 0.8%
Published 2006-06-12 · Affected: <1.0
Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in
CVE-2006-2964 UNKNOWN EPSS 0.8%
Published 2006-06-12 · Affected: <1.0
Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in

Is Download Manager running on your site?

A free scan detects your plugins and flags any that match these CVEs.

Scan My Site Free