ayecode kayıtları
ayecode üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %47,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-862 Missing Authorization3
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-340 Generation of Predictable Numbers or Identifiers1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-6265Kavram kanıtı | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sortayecode · userswp · CWE-89 | Kritik9,8 | — | %2,4 | 29 Haz 2024 |
40Planlayın | CVE-2021-24361İstismar yok | GeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injectionsayecode · location manager · CWE-89 | Kritik9,8 | — | %1,8 | 21 Haz 2021 |
35İzleyin | CVE-2022-47442İstismar yok | WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injectionayecode · userswp · CWE-1236 | Yüksek8,8 | — | %0,7 | 7 Kas 2023 |
35İzleyin | CVE-2024-43973İstismar yok | WordPress GetPaid plugin <= 2.8.11 - Broken Access Control vulnerabilityayecode · getpaid · CWE-862 | Yüksek8,8 | — | %0,5 | 1 Kas 2024 |
35İzleyin | CVE-2024-43145İstismar yok | WordPress GeoDirectory plugin <= 2.3.61 - SQL Injection vulnerabilityayecode · geodirectory · CWE-89 | Yüksek8,8 | — | %0,4 | 18 Ağu 2024 |
35İzleyin | CVE-2024-43981İstismar yok | WordPress GeoDirectory plugin <= 2.3.70 - Broken Access Control vulnerabilityayecode · geodirectory · CWE-862 | Yüksek8,8 | — | %0,4 | 1 Kas 2024 |
30İzleyin | CVE-2024-6477İstismar yok | UsersWP < 1.2.12 - Users Information Disclosureayecode · userswp · CWE-340 | Yüksek7,5 | — | %0,6 | 3 Ağu 2024 |
28İzleyin | CVE-2023-50845İstismar yok | WordPress GeoDirectory Plugin <= 2.3.28 is vulnerable to SQL Injectionayecode · geodirectory · CWE-89 | Yüksek7,2 | — | %0,5 | 28 Ara 2023 |
25İzleyin | CVE-2024-2423İstismar yok | UsersWP <= 1.2.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcodeayecode · userswp · CWE-79 | Orta6,4 | — | %0,4 | 9 Nis 2024 |
24İzleyin | CVE-2023-2813Kavram kanıtı | Multiple Themes - Reflected XSSajaydsouza · connections reloaded · CWE-79 | Orta6,1 | — | %1,0 | 4 Eyl 2023 |
23İzleyin | CVE-2025-6200İstismar yok | GeoDirectory < 2.8.120 - Contributor+ Stored XSSayecode · geodirectory · CWE-79 | Orta5,9 | — | %0,2 | 11 Tem 2025 |
21İzleyin | CVE-2021-24720İstismar yok | GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)ayecode · geodirectory · CWE-79 | Orta5,4 | — | %0,9 | 11 Eki 2021 |
21İzleyin | CVE-2021-24369İstismar yok | GetPaid < 2.3.4 - Authenticated Stored XSSayecode · getpaid · CWE-79 | Orta5,4 | — | %0,6 | 21 Haz 2021 |
21İzleyin | CVE-2022-4775İstismar yok | GeoDirectory < 2.2.22 - Contributor+ Stored XSS via Shortcodeayecode · geodirectory · CWE-79 | Orta5,4 | — | %0,5 | 23 Oca 2023 |
21İzleyin | CVE-2024-43277İstismar yok | WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerabilityayecode ltd · userswp · CWE-862 | Orta5,3 | — | %0,4 | 1 Kas 2024 |
21İzleyin | CVE-2024-56259İstismar yok | WordPress GeoDirectory plugin <= 2.3.84 - Cross Site Scripting (XSS) vulnerabilityayecode · geodirectory · CWE-79 | Orta5,4 | — | %0,3 | 2 Oca 2025 |
21İzleyin | CVE-2024-3732İstismar yok | GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_ayecode · geodirectory · CWE-79 | Orta5,4 | — | %0,3 | 23 Nis 2024 |
21İzleyin | CVE-2024-50437İstismar yok | WordPress GeoDirectory plugin <= 2.3.80 - Cross Site Scripting (XSS) vulnerabilityayecode · geodirectory · CWE-79 | Orta5,4 | — | %0,2 | 28 Eki 2024 |
21İzleyin | CVE-2024-13590İstismar yok | Ketchup Shortcodes <= 0.1.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingayecode · ketchup shortcodes · CWE-79 | Orta5,4 | — | %0,2 | 22 Oca 2025 |
17İzleyin | CVE-2022-0442İstismar yok | UsersWP < 1.2.3.1 - Subscriber+ User Avatar Overrideayecode · userswp · CWE-639 | Orta4,3 | — | %0,7 | 7 Mar 2022 |
17İzleyin | CVE-2022-29453İstismar yok | WordPress API KEY for Google Maps plugin <= 1.2.1 - CSRF vulnerability leading to Google Maps API key updateayecode · api key for google maps · CWE-352 | Orta4,3 | — | %0,4 | 15 Haz 2022 |
- CVE-2024-626540Planlayın
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort
KritikCVSS 9,8Kavram kanıtıEPSS %2ayecode · userswp29 Haz 2024
- CVE-2021-2436140Planlayın
GeoDirectory Location Manager < 2.1.0.10 - Multiple Unauthenticated SQL Injections
KritikCVSS 9,8İstismar yokEPSS %2ayecode · location manager21 Haz 2021
- CVE-2022-4744235İzleyin
WordPress UsersWP Plugin <= 1.2.3.9 is vulnerable to CSV Injection
YüksekCVSS 8,8İstismar yokEPSS %1ayecode · userswp7 Kas 2023
- CVE-2024-4397335İzleyin
WordPress GetPaid plugin <= 2.8.11 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0ayecode · getpaid1 Kas 2024
- CVE-2024-4314535İzleyin
WordPress GeoDirectory plugin <= 2.3.61 - SQL Injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0ayecode · geodirectory18 Ağu 2024
- CVE-2024-4398135İzleyin
WordPress GeoDirectory plugin <= 2.3.70 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0ayecode · geodirectory1 Kas 2024
- CVE-2024-647730İzleyin
UsersWP < 1.2.12 - Users Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %1ayecode · userswp3 Ağu 2024
- CVE-2023-5084528İzleyin
WordPress GeoDirectory Plugin <= 2.3.28 is vulnerable to SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1ayecode · geodirectory28 Ara 2023
- CVE-2024-242325İzleyin
UsersWP <= 1.2.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 6,4İstismar yokEPSS %0ayecode · userswp9 Nis 2024
- CVE-2023-281324İzleyin
Multiple Themes - Reflected XSS
OrtaCVSS 6,1Kavram kanıtıEPSS %1ajaydsouza · connections reloaded4 Eyl 2023
- CVE-2025-620023İzleyin
GeoDirectory < 2.8.120 - Contributor+ Stored XSS
OrtaCVSS 5,9İstismar yokEPSS %0ayecode · geodirectory11 Tem 2025
- CVE-2021-2472021İzleyin
GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %1ayecode · geodirectory11 Eki 2021
- CVE-2021-2436921İzleyin
GetPaid < 2.3.4 - Authenticated Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1ayecode · getpaid21 Haz 2021
- CVE-2022-477521İzleyin
GeoDirectory < 2.2.22 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0ayecode · geodirectory23 Oca 2023
- CVE-2024-4327721İzleyin
WordPress UsersWP plugin <= 1.2.15 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0ayecode ltd · userswp1 Kas 2024
- CVE-2024-5625921İzleyin
WordPress GeoDirectory plugin <= 2.3.84 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0ayecode · geodirectory2 Oca 2025
- CVE-2024-373221İzleyin
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_
OrtaCVSS 5,4İstismar yokEPSS %0ayecode · geodirectory23 Nis 2024
- CVE-2024-5043721İzleyin
WordPress GeoDirectory plugin <= 2.3.80 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0ayecode · geodirectory28 Eki 2024
- CVE-2024-1359021İzleyin
Ketchup Shortcodes <= 0.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0ayecode · ketchup shortcodes22 Oca 2025
- CVE-2022-044217İzleyin
UsersWP < 1.2.3.1 - Subscriber+ User Avatar Override
OrtaCVSS 4,3İstismar yokEPSS %1ayecode · userswp7 Mar 2022
- CVE-2022-2945317İzleyin
WordPress API KEY for Google Maps plugin <= 1.2.1 - CSRF vulnerability leading to Google Maps API key update
OrtaCVSS 4,3İstismar yokEPSS %0ayecode · api key for google maps15 Haz 2022