PatchSiren

Simple File List CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Simple File List CVE published 2026-08-19

CVE-2026-16617

AI-assisted PatchSiren debrief based on the supplied source corpus. The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public file list, allowing unauthenticated users (when front-end file management is enabled) to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the list. [truncated]

HIGH Simple File List CVE published 2026-08-19

CVE-2026-16616

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover. This vulnerability is caused by a lack of input validation and sanitization in the [truncated]