Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

nmedia — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting nmedia. AI-powered Chinese analysis, POCs, and references for each vulnerability.

nmedia operates primarily as a provider of digital signage and content management solutions, enabling enterprises to display multimedia content across distributed networks. Security audits have identified twenty-three distinct Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem, indicating a persistent history of security flaws. The most prevalent vulnerability classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which often stem from insufficient input validation and improper access controls within the web-based management interfaces. Additionally, several instances of privilege escalation have been documented, allowing unauthorized users to gain administrative rights. These issues suggest that nmedia’s architecture has historically struggled with robust security hygiene, particularly regarding authentication mechanisms and data sanitization. While no single catastrophic public breach has been widely reported, the cumulative nature of these CVEs highlights significant risks for organizations relying on its platform for critical visual communications, necessitating rigorous patch management and network segmentation.

Found 11 results / 23Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-1280 Frontend File Manager Plugin <= 23.5 - Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter — Frontend File Manager PluginCWE-862 7.5 High2026-01-28
CVE-2025-13382 Frontend File Manager Plugin <= 23.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming — Frontend File Manager PluginCWE-639 4.3 Medium2025-11-25
CVE-2023-7306 Frontend File Manager <= 21.5 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Frontend File Manager PluginCWE-862 7.5 High2025-07-25
CVE-2021-4369 Frontend File Manager <= 18.2 - Unauthenticated Content Injection — Frontend File Manager PluginCWE-862 5.8 Medium2023-06-07
CVE-2021-4368 Frontend File Manager <= 18.2 - Authenticated Settings Change leading to Arbitrary File Upload — Frontend File Manager PluginCWE-862 9.9 Critical2023-06-07
CVE-2021-4365 Frontend File Manager <= 18.2 - Unauthenticated Stored Cross-Site Scripting — Frontend File Manager PluginCWE-79 7.2 High2023-06-07
CVE-2021-4359 Frontend File Manager Plugin <= 18.2 - Unauthenticated Arbitrary Post Deletion — Frontend File Manager PluginCWE-862 6.5 Medium2023-06-07
CVE-2021-4356 Frontend File Manager <= 18.2 - Unauthenticated Arbitrary File Download — Frontend File Manager PluginCWE-862 9.0 Critical2023-06-07
CVE-2021-4351 Frontend File Manager <= 18.2 - Unauthenticated Post Meta Change — Frontend File Manager PluginCWE-862 5.8 Medium2023-06-07
CVE-2021-4350 Frontend File Manager <= 18.2 - Unauthenticated HTML Injection leading to Spam Emails — Frontend File Manager PluginCWE-862 7.2 High2023-06-07
CVE-2021-4344 Frontend File Manager <= 18.2 - Privilege Escalation — Frontend File Manager PluginCWE-285 6.4 Medium2023-06-07

This page lists every published CVE security advisory associated with nmedia. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.