CVE-2026-25005: N-Media Frontend File Manager

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.

Affected products

  • N-Media Frontend File Manager: up to and including 23.5

Published 2026-02-19. Last modified 2026-06-17.