VendorsTips and Tricks HQsimple_download_monitorall versions
Vulnerabilities

Tips and Tricks HQ Simple Download Monitor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-24693
Simple Download Monitor < 3.9.5 - Contributor+ Stored Cross-Site Scripting via File Thumbnail
Published 2021-11-08 · Modified
9.0EPSS 0.013
CVE-2020-5651
SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.
Published 2020-10-21 · Modified
8.8EPSS 0.015
CVE-2021-24696
Simple Download Monitor < 3.9.9 - Multiple CSRF
Published 2022-01-24 · Modified
8.8EPSS 0.006
CVE-2021-24695
Simple Download Monitor < 3.9.6 - Unauthenticated Log Access
Published 2021-11-08 · Modified
7.5EPSS 0.017
CVE-2021-24692
Simple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path Traversal
Published 2022-03-14 · Modified
6.5EPSS 0.014
CVE-2020-5650
Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
Published 2020-10-21 · Modified
6.1EPSS 0.009
CVE-2021-24697
Simple Download Monitor < 3.9.5 - Reflected Cross-Site Scripting
Published 2021-11-08 · Modified
6.1EPSS 0.008
CVE-2021-24694
Simple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via Shortcodes
Published 2022-01-24 · Modified
5.4EPSS 0.006
CVE-2021-24698
Simple Download Monitor < 3.9.6 - Arbitrary Thumbnails Removal
Published 2021-11-08 · Modified
4.3EPSS 0.007