CVE-2025-46001: Simogeo Filemanager

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Affected products

  • Simogeo Filemanager: from 0.8, up to and including 1.1; from 1.5.0, up to and including 2.0.0

Published 2025-07-18. Last modified 2026-06-17.