cleantalk
Vulnerabilities and Security Researches

Frontend File Manager Plugin, CVE-2026-25005

CVE, Research URL

CVE-2026-25005

Published on
Feb 19, 2026
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.
Affected versions
max 23.5.
Status
vulnerable