Simple download monitor
This hub aggregates every CVE we track for Simple download monitor, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM10HIGH4CRITICAL1
Monthly trend
0
0
0
1
0
0
0
0
0
0
2
0
0
0
0
0
1
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Simple download monitor.
- CVE-2026-2383Simple Download Monitor <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field6.4
- CVE-2025-8977Simple Download Monitor <= 3.9.33 - Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality6.5
- CVE-2025-58197WordPress Simple Download Monitor Plugin <= 3.9.34 - Cross Site Scripting (XSS) Vulnerability6.5
- CVE-2025-24663WordPress Simple Download Monitor plugin <= 3.9.25 - SQL Injection vulnerability7.6
- CVE-2021-24692Simple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path Traversal6.5
- CVE-2021-24696Simple Download Monitor < 3.9.9 - Multiple CSRF8.8
- CVE-2021-24694Simple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via Shortcodes5.4
- CVE-2021-24698Simple Download Monitor < 3.9.6 - Arbitrary Thumbnails Removal4.3
- CVE-2021-24697Simple Download Monitor < 3.9.5 - Reflected Cross-Site Scripting6.1
- CVE-2021-24695Simple Download Monitor < 3.9.6 - Unauthenticated Log Access7.5
- CVE-2021-24693Simple Download Monitor < 3.9.5 - Contributor+ Stored Cross-Site Scripting via File Thumbnail9.0
- CVE-2020-5651SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL.8.8
- CVE-2020-5650Cross-site scripting vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.6.1
- CVE-2018-5212The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.5.4
- CVE-2018-5213The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.5.4
Product normalization is registry-driven with AI assist and human review. How it works