Hiro (Code016Hiro)
Patchstack Bug Bounty Program
17 kredili kayıt · son 12 ayda 0 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
21İzleyin | CVE-2025-57921İstismar yok | WordPress Frontend File Manager plugin <= 23.3 - Broken Access Control vulnerabilityn-media · frontend file manager · CWE-862 | Orta5,3 | — | %0,3 | 22 Eyl 2025 |
21İzleyin | CVE-2025-58797İstismar yok | WordPress Ninja Charts plugin <= 3.3.5 - Sensitive Data Exposure vulnerabilitymahmudul hasan arif · ninja charts · CWE-497 | Orta5,3 | — | %0,3 | 5 Eyl 2025 |
21İzleyin | CVE-2025-58603İstismar yok | WordPress Surfer Plugin <= 1.6.4.574 - Broken Access Control Vulnerabilitysurfer · surfer · CWE-862 | Orta5,3 | — | %0,3 | 3 Eyl 2025 |
39İzleyin | CVE-2025-54049İstismar yok | WordPress Custom API for WP <= 4.2.2 - Privilege Escalation Vulnerabilityminiorange · custom api for wp · CWE-266 | Kritik9,9 | — | %0,4 | 20 Ağu 2025 |
37İzleyin | CVE-2025-54048İstismar yok | WordPress Custom API for WP <= 4.2.2 - SQL Injection Vulnerabilityminiorange · custom api for wp · CWE-89 | Kritik9,3 | — | %0,4 | 20 Ağu 2025 |
26İzleyin | CVE-2025-54040İstismar yok | WordPress Webba Booking <= 5.1.20 - Broken Access Control Vulnerabilitywebba appointment booking · webba booking · CWE-862 | Orta6,5 | — | %0,4 | 20 Ağu 2025 |
32İzleyin | CVE-2025-52818İstismar yok | WordPress Trusty Whistleblowing plugin <= 2.0.1 - Broken Access Control vulnerabilitydejan jasnic · trusty whistleblowing · CWE-862 | Yüksek8,2 | — | %0,3 | 27 Haz 2025 |
21İzleyin | CVE-2025-49989İstismar yok | WordPress App Builder plugin <= 5.5.6 - Broken Access Control vulnerabilityapp cheap · app builder · CWE-862 | Orta5,3 | — | %0,3 | 20 Haz 2025 |
30İzleyin | CVE-2025-28972İstismar yok | WordPress WP Employee Attendance System plugin <= 3.5 - SQL Injection Vulnerabilitysuhas surse · wp employee attendance system · CWE-89 | Yüksek7,6 | — | %0,4 | 17 Haz 2025 |
18İzleyin | CVE-2025-49325İstismar yok | WordPress Newspack Newsletters plugin <= 3.13.0 - Open Redirection Vulnerabilityautomattic · newspack newsletters · CWE-601 | Orta4,7 | — | %0,3 | 6 Haz 2025 |
21İzleyin | CVE-2025-49324İstismar yok | WordPress Job Board Manager plugin <= 2.1.60 - Broken Access Control Vulnerabilitypickplugins · job board manager · CWE-862 | Orta5,3 | — | %0,3 | 6 Haz 2025 |
21İzleyin | CVE-2025-30945İstismar yok | WordPress Taskbuilder plugin <= 4.0.7 - Broken Access Control Vulnerabilitytaskbuilder · taskbuilder · CWE-862 | Orta5,3 | — | %0,3 | 6 Haz 2025 |
17İzleyin | CVE-2025-29005İstismar yok | WordPress HR Management Lite plugin <= 3.6 - Cross Site Request Forgery (CSRF) vulnerabilityweblizar - wordpress themes & plugin · hr management lite · CWE-352 | Orta4,3 | — | %0,2 | 6 Haz 2025 |
21İzleyin | CVE-2025-28997İstismar yok | WordPress WP AutoKeyword plugin <= 1.0 - Broken Access Control Vulnerabilityexeideas international · wp autokeyword · CWE-862 | Orta5,3 | — | %0,3 | 6 Haz 2025 |
21İzleyin | CVE-2025-28985İstismar yok | WordPress Elastic Email Subscribe Form plugin <= 1.2.2 - Broken Access Control Vulnerabilityelastic email · elastic email subscribe form · CWE-862 | Orta5,4 | — | %0,3 | 6 Haz 2025 |
28İzleyin | CVE-2025-48241İstismar yok | WordPress Verge3D plugin <= 4.9.3 - Reflected Cross Site Scripting (XSS) vulnerabilitysoft8soft llc · verge3d · CWE-79 | Yüksek7,1 | — | %0,2 | 23 May 2025 |
37İzleyin | CVE-2025-46455İstismar yok | WordPress WP HRM LITE plugin <= 1.1 - SQL Injection Vulnerabilityindigothemes · wp hrm lite · CWE-89 | Kritik9,3 | — | %0,4 | 23 May 2025 |
- CVE-2025-5792121İzleyin
WordPress Frontend File Manager plugin <= 23.3 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0n-media · frontend file manager22 Eyl 2025
- CVE-2025-5879721İzleyin
WordPress Ninja Charts plugin <= 3.3.5 - Sensitive Data Exposure vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0mahmudul hasan arif · ninja charts5 Eyl 2025
- CVE-2025-5860321İzleyin
WordPress Surfer Plugin <= 1.6.4.574 - Broken Access Control Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0surfer · surfer3 Eyl 2025
- CVE-2025-5404939İzleyin
WordPress Custom API for WP <= 4.2.2 - Privilege Escalation Vulnerability
KritikCVSS 9,9İstismar yokEPSS %0miniorange · custom api for wp20 Ağu 2025
- CVE-2025-5404837İzleyin
WordPress Custom API for WP <= 4.2.2 - SQL Injection Vulnerability
KritikCVSS 9,3İstismar yokEPSS %0miniorange · custom api for wp20 Ağu 2025
- CVE-2025-5404026İzleyin
WordPress Webba Booking <= 5.1.20 - Broken Access Control Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0webba appointment booking · webba booking20 Ağu 2025
- CVE-2025-5281832İzleyin
WordPress Trusty Whistleblowing plugin <= 2.0.1 - Broken Access Control vulnerability
YüksekCVSS 8,2İstismar yokEPSS %0dejan jasnic · trusty whistleblowing27 Haz 2025
- CVE-2025-4998921İzleyin
WordPress App Builder plugin <= 5.5.6 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0app cheap · app builder20 Haz 2025
- CVE-2025-2897230İzleyin
WordPress WP Employee Attendance System plugin <= 3.5 - SQL Injection Vulnerability
YüksekCVSS 7,6İstismar yokEPSS %0suhas surse · wp employee attendance system17 Haz 2025
- CVE-2025-4932518İzleyin
WordPress Newspack Newsletters plugin <= 3.13.0 - Open Redirection Vulnerability
OrtaCVSS 4,7İstismar yokEPSS %0automattic · newspack newsletters6 Haz 2025
- CVE-2025-4932421İzleyin
WordPress Job Board Manager plugin <= 2.1.60 - Broken Access Control Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0pickplugins · job board manager6 Haz 2025
- CVE-2025-3094521İzleyin
WordPress Taskbuilder plugin <= 4.0.7 - Broken Access Control Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0taskbuilder · taskbuilder6 Haz 2025
- CVE-2025-2900517İzleyin
WordPress HR Management Lite plugin <= 3.6 - Cross Site Request Forgery (CSRF) vulnerability
OrtaCVSS 4,3İstismar yokEPSS %0weblizar - wordpress themes & plugin · hr management lite6 Haz 2025
- CVE-2025-2899721İzleyin
WordPress WP AutoKeyword plugin <= 1.0 - Broken Access Control Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0exeideas international · wp autokeyword6 Haz 2025
- CVE-2025-2898521İzleyin
WordPress Elastic Email Subscribe Form plugin <= 1.2.2 - Broken Access Control Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0elastic email · elastic email subscribe form6 Haz 2025
- CVE-2025-4824128İzleyin
WordPress Verge3D plugin <= 4.9.3 - Reflected Cross Site Scripting (XSS) vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0soft8soft llc · verge3d23 May 2025
- CVE-2025-4645537İzleyin
WordPress WP HRM LITE plugin <= 1.1 - SQL Injection Vulnerability
KritikCVSS 9,3İstismar yokEPSS %0indigothemes · wp hrm lite23 May 2025