cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forz-downloads z-downloads

Direction: ascending
Jun 07, 2024

Z-Downloads # CVE-2024-34555

CVE, Research URL

CVE-2024-34555

Application

Z-Downloads

Date
May 14, 2024
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.
Affected versions
Min -, max -.
Status
vulnerable
Dec 08, 2024

Z-Downloads # CVE-2024-54206

CVE, Research URL

CVE-2024-54206

Application

Z-Downloads

Date
Dec 06, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downloads allows Stored XSS.This issue affects Z-Downloads: from n/a through 1.11.7.
Affected versions
Min -, max -.
Status
vulnerable
May 19, 2025

Z-Downloads # CVE-2024-8673

CVE, Research URL

CVE-2024-8673

Application

Z-Downloads

Date
May 16, 2025
Research Description
The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.
Affected versions
Min -, max -.
Status
vulnerable

Z-Downloads # CVE-2024-8699

CVE, Research URL

CVE-2024-8699

Application

Z-Downloads

Date
May 16, 2025
Research Description
The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable

Z-Downloads # CVE-2024-8703

CVE, Research URL

CVE-2024-8703

Application

Z-Downloads

Date
May 16, 2025
Research Description
The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.
Affected versions
Min -, max -.
Status
vulnerable