Ex.Mi (Patchstack)
29 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2022-29434No exploit | WordPress Spiffy Calendar plugin <= 4.9.0 - Edit/Delete event via IDOR vulnerabilityspiffyplugins · spiffy calendar · CWE-639 | Medium5.4 | — | 0.7% | May 20, 2022 |
19Monitor | CVE-2022-29432No exploit | WordPress wpDataTables plugin <= 2.1.27 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitiestms-outsource · wpdatatables · CWE-79 | Medium4.8 | — | 0.5% | May 20, 2022 |
39Monitor | CVE-2022-29423No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Pro Features Lock Bypass vulnerabilityedmonsoft · countdown builder · CWE-264 | Critical9.8 | — | 1.1% | May 6, 2022 |
19Monitor | CVE-2022-29422No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitiesedmonsoft · countdown builder · CWE-79 | Medium4.8 | — | 0.6% | May 6, 2022 |
24Monitor | CVE-2022-29421No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Reflected Cross-Site Scripting (XSS) vulnerabilityedmonsoft · countdown builder · CWE-79 | Medium6.1 | — | 0.8% | May 6, 2022 |
21Monitor | CVE-2022-29414No exploit | WordPress Subscribe To Comments Reloaded plugin <= 211130 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilitieswpkube · subscribe to comments reloaded · CWE-352 | Medium5.4 | — | 0.4% | Apr 29, 2022 |
24Monitor | CVE-2022-29413No exploit | WordPress Hermit 音乐播放器 plugin <= 3.1.6 - Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerabilityhermit project · hermit · CWE-79 | Medium6.1 | — | 0.4% | Apr 28, 2022 |
21Monitor | CVE-2022-29412No exploit | WordPress Hermit 音乐播放器 plugin <= 3.1.6 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilitieshermit project · hermit · CWE-352 | Medium5.4 | — | 0.4% | Apr 28, 2022 |
21Monitor | CVE-2022-27854No exploit | WordPress Psychological tests & quizzes plugin <= 0.21.19 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitypsychological tests \& quizzes project · psychological tests \& quizzes · CWE-79 | Medium5.4 | — | 0.6% | Apr 26, 2022 |
19Monitor | CVE-2022-29418No exploit | WordPress Night Mode plugin <= 1.0.0 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitynight mode project · night mode · CWE-79 | Medium4.8 | — | 0.5% | Apr 25, 2022 |
32Monitor | CVE-2022-23976No exploit | WordPress Access Demo Importer plugin <= 1.0.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Data Reset (Posts / Pages / Media)accesspressthemes · access demo importer · CWE-352 | High8.1 | — | 0.5% | Apr 18, 2022 |
26Monitor | CVE-2022-23975No exploit | WordPress Access Demo Importer plugin <= 1.0.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary Plugin Activationaccesspressthemes · access demo importer · CWE-352 | Medium6.5 | — | 0.5% | Apr 18, 2022 |
17Monitor | CVE-2022-27850No exploit | WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilityplugin-planet · simple ajax chat · CWE-352 | Medium4.3 | — | 0.4% | Apr 15, 2022 |
31Monitor | CVE-2022-27849Proof of concept | WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerabilityplugin-planet · simple ajax chat · CWE-200 | High7.5 | — | 4.6% | Apr 15, 2022 |
17Monitor | CVE-2022-27847No exploit | WordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Template Importyooslider · yoo slider · CWE-352 | Medium4.3 | — | 0.4% | Apr 13, 2022 |
17Monitor | CVE-2022-27846No exploit | WordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Slider Creation / Modificationyooslider · yoo slider · CWE-352 | Medium4.3 | — | 0.4% | Apr 13, 2022 |
17Monitor | CVE-2022-25615No exploit | WordPress eRoom plugin <= 1.3.8 - Cross-Site Request Forgery (CSRF) vulnerability leading to Cache Deletionstylemixthemes · eroom - zoom meetings \& webinar · CWE-352 | Medium4.3 | — | 0.4% | Apr 11, 2022 |
17Monitor | CVE-2022-25614No exploit | WordPress eRoom plugin <= 1.3.7 - Cross-Site Request Forgery (CSRF) leading to Sync with Zoom Meetings vulnerabilitystylemixthemes · eroom - zoom meetings \& webinar · CWE-352 | Medium4.3 | — | 0.4% | Apr 11, 2022 |
21Monitor | CVE-2022-25613No exploit | WordPress FV Flowplayer Video Player plugin <= 7.5.18.727 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilityfoliovision · fv flowplayer video player · CWE-79 | Medium5.4 | — | 0.6% | Apr 4, 2022 |
21Monitor | CVE-2022-25612No exploit | WordPress Simple Event Planner plugin <= 1.5.4 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitiespresstigers · simple event planner · CWE-79 | Medium5.4 | — | 0.6% | Mar 25, 2022 |
21Monitor | CVE-2022-25606No exploit | WordPress WP-DownloadManager plugin <= 1.68.5 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswp-downloadmanager project · wp-downloadmanager · CWE-79 | Medium5.4 | — | 0.6% | Mar 25, 2022 |
21Monitor | CVE-2022-25605No exploit | WordPress WP-DownloadManager plugin <= 1.68.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswp-downloadmanager project · wp-downloadmanager · CWE-79 | Medium5.4 | — | 0.6% | Mar 18, 2022 |
24Monitor | CVE-2022-25601No exploit | WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerabilityplugin-planet · contact form x · CWE-79 | Medium6.1 | — | 1.0% | Mar 11, 2022 |
35Monitor | CVE-2022-25600No exploit | WordPress WP Google Map plugin <= 4.2.3 - Cross-Site Request Forgery (CSRF) vulnerabilityweplugins · wp maps · CWE-352 | High8.8 | — | 0.6% | Mar 11, 2022 |
27Monitor | CVE-2021-31567No exploit | WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilitywpchill · download monitor · CWE-200 | Medium6.8 | — | 1.4% | Jan 28, 2022 |
- CVE-2022-2943421Monitor
WordPress Spiffy Calendar plugin <= 4.9.0 - Edit/Delete event via IDOR vulnerability
MediumCVSS 5.4No exploitEPSS 1%spiffyplugins · spiffy calendarMay 20, 2022
- CVE-2022-2943219Monitor
WordPress wpDataTables plugin <= 2.1.27 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 4.8No exploitEPSS 1%tms-outsource · wpdatatablesMay 20, 2022
- CVE-2022-2942339Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Pro Features Lock Bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 1%edmonsoft · countdown builderMay 6, 2022
- CVE-2022-2942219Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 4.8No exploitEPSS 1%edmonsoft · countdown builderMay 6, 2022
- CVE-2022-2942124Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%edmonsoft · countdown builderMay 6, 2022
- CVE-2022-2941421Monitor
WordPress Subscribe To Comments Reloaded plugin <= 211130 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
MediumCVSS 5.4No exploitEPSS 0%wpkube · subscribe to comments reloadedApr 29, 2022
- CVE-2022-2941324Monitor
WordPress Hermit 音乐播放器 plugin <= 3.1.6 - Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%hermit project · hermitApr 28, 2022
- CVE-2022-2941221Monitor
WordPress Hermit 音乐播放器 plugin <= 3.1.6 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
MediumCVSS 5.4No exploitEPSS 0%hermit project · hermitApr 28, 2022
- CVE-2022-2785421Monitor
WordPress Psychological tests & quizzes plugin <= 0.21.19 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%psychological tests \& quizzes project · psychological tests \& quizzesApr 26, 2022
- CVE-2022-2941819Monitor
WordPress Night Mode plugin <= 1.0.0 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 1%night mode project · night modeApr 25, 2022
- CVE-2022-2397632Monitor
WordPress Access Demo Importer plugin <= 1.0.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Data Reset (Posts / Pages / Media)
HighCVSS 8.1No exploitEPSS 0%accesspressthemes · access demo importerApr 18, 2022
- CVE-2022-2397526Monitor
WordPress Access Demo Importer plugin <= 1.0.7 - Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary Plugin Activation
MediumCVSS 6.5No exploitEPSS 0%accesspressthemes · access demo importerApr 18, 2022
- CVE-2022-2785017Monitor
WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%plugin-planet · simple ajax chatApr 15, 2022
- CVE-2022-2784931Monitor
WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability
HighCVSS 7.5Proof of conceptEPSS 5%plugin-planet · simple ajax chatApr 15, 2022
- CVE-2022-2784717Monitor
WordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Template Import
MediumCVSS 4.3No exploitEPSS 0%yooslider · yoo sliderApr 13, 2022
- CVE-2022-2784617Monitor
WordPress Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Slider Creation / Modification
MediumCVSS 4.3No exploitEPSS 0%yooslider · yoo sliderApr 13, 2022
- CVE-2022-2561517Monitor
WordPress eRoom plugin <= 1.3.8 - Cross-Site Request Forgery (CSRF) vulnerability leading to Cache Deletion
MediumCVSS 4.3No exploitEPSS 0%stylemixthemes · eroom - zoom meetings \& webinarApr 11, 2022
- CVE-2022-2561417Monitor
WordPress eRoom plugin <= 1.3.7 - Cross-Site Request Forgery (CSRF) leading to Sync with Zoom Meetings vulnerability
MediumCVSS 4.3No exploitEPSS 0%stylemixthemes · eroom - zoom meetings \& webinarApr 11, 2022
- CVE-2022-2561321Monitor
WordPress FV Flowplayer Video Player plugin <= 7.5.18.727 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 1%foliovision · fv flowplayer video playerApr 4, 2022
- CVE-2022-2561221Monitor
WordPress Simple Event Planner plugin <= 1.5.4 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%presstigers · simple event plannerMar 25, 2022
- CVE-2022-2560621Monitor
WordPress WP-DownloadManager plugin <= 1.68.5 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%wp-downloadmanager project · wp-downloadmanagerMar 25, 2022
- CVE-2022-2560521Monitor
WordPress WP-DownloadManager plugin <= 1.68.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%wp-downloadmanager project · wp-downloadmanagerMar 18, 2022
- CVE-2022-2560124Monitor
WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%plugin-planet · contact form xMar 11, 2022
- CVE-2022-2560035Monitor
WordPress WP Google Map plugin <= 4.2.3 - Cross-Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 1%weplugins · wp mapsMar 11, 2022
- CVE-2021-3156727Monitor
WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerability
MediumCVSS 6.8No exploitEPSS 1%wpchill · download monitorJan 28, 2022