androidbubbles records
7 published records for vendor androidbubbles.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization2
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-47321No exploit | WordPress WP Datepicker plugin <= 2.1.1 - Broken Access Control vulnerabilityandroidbubbles · wp datepicker · CWE-862 | Critical9.8 | — | 0.4% | Nov 1, 2024 |
35Monitor | CVE-2024-3895No exploit | WP Datepicker <= 2.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Updateandroidbubbles · wp datepicker · CWE-862 | High8.8 | — | 0.9% | May 2, 2024 |
24Monitor | CVE-2022-1820No exploit | Keep Backup Daily <= 2.0.2 - Reflected Cross-Site Scriptingandroidbubbles · keep backup daily · CWE-79 | Medium6.1 | — | 1.1% | Jun 13, 2022 |
24Monitor | CVE-2021-24798No exploit | WP Header Images < 2.0.1 - Reflected Cross-Site Scriptingandroidbubbles · wp header images · CWE-79 | Medium6.1 | — | 0.8% | Nov 8, 2021 |
24Monitor | CVE-2024-12468No exploit | WP Datepicker <= 2.1.4 - Reflected Cross-Site Scriptingandroidbubbles · wp datepicker · CWE-79 | Medium6.1 | — | 0.5% | Dec 24, 2024 |
24Monitor | CVE-2024-49629No exploit | WordPress Endless Posts Navigation plugin <= 2.2.7 - CSRF to Stored XSS vulnerabilityandroidbubbles · endless posts navigation · CWE-352 | Medium6.1 | — | 0.2% | Oct 20, 2024 |
19Monitor | CVE-2024-44042No exploit | WordPress WP Datepicker plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerabilityandroidbubbles · wp datepicker · CWE-79 | Medium4.8 | — | 0.3% | Oct 6, 2024 |
- CVE-2024-4732139Monitor
WordPress WP Datepicker plugin <= 2.1.1 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%androidbubbles · wp datepickerNov 1, 2024
- CVE-2024-389535Monitor
WP Datepicker <= 2.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
HighCVSS 8.8No exploitEPSS 1%androidbubbles · wp datepickerMay 2, 2024
- CVE-2022-182024Monitor
Keep Backup Daily <= 2.0.2 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%androidbubbles · keep backup dailyJun 13, 2022
- CVE-2021-2479824Monitor
WP Header Images < 2.0.1 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%androidbubbles · wp header imagesNov 8, 2021
- CVE-2024-1246824Monitor
WP Datepicker <= 2.1.4 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%androidbubbles · wp datepickerDec 24, 2024
- CVE-2024-4962924Monitor
WordPress Endless Posts Navigation plugin <= 2.2.7 - CSRF to Stored XSS vulnerability
MediumCVSS 6.1No exploitEPSS 0%androidbubbles · endless posts navigationOct 20, 2024
- CVE-2024-4404219Monitor
WordPress WP Datepicker plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%androidbubbles · wp datepickerOct 6, 2024