Записи BoldGrid
27 опубликованных записей вендора boldgrid.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 7,4 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 14,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-862 Missing Authorization3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2013-2010Готовый эксплойт | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerabilityautomattic · wp super cache · CWE-74 | Критическая9,8 | — | 73,9 % | 12 февр. 2020 г. |
36Наблюдать | CVE-2019-6715Proof of concept | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL fieboldgrid · w3 total cache | Высокая7,5 | — | 19,4 % | 1 апр. 2019 г. |
35Наблюдать | CVE-2024-12365Proof of concept | W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgeryboldgrid · w3 total cache · CWE-862 | Высокая8,5 | — | 1,8 % | 14 янв. 2025 г. |
35Наблюдать | CVE-2023-25480Эксплойта нет | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF)boldgrid · post and page builder · CWE-352 | Высокая8,8 | — | 0,3 % | 6 окт. 2023 г. |
32Наблюдать | CVE-2012-6077Proof of concept | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.boldgrid · w3 total cache · CWE-200 | Высокая7,5 | — | 5,4 % | 22 нояб. 2019 г. |
31Наблюдать | CVE-2012-6078Эксплойта нет | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.boldgrid · w3 total cache · CWE-200 | Высокая7,5 | — | 2,3 % | 22 нояб. 2019 г. |
31Наблюдать | CVE-2024-12008Proof of concept | W3 Total Cache <= 2.8.1 Information Exposure via Log Filesboldgrid · w3 total cache · CWE-200 | Высокая7,5 | — | 2,3 % | 14 янв. 2025 г. |
31Наблюдать | CVE-2012-6079Эксплойта нет | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via tboldgrid · w3 total cache · CWE-200 | Высокая7,5 | — | 2,1 % | 22 нояб. 2019 г. |
30Наблюдать | CVE-2020-36848Готовый эксплойт | Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Downloadboldgrid · total upkeep · CWE-200 | Высокая7,5 | — | 1,6 % | 12 июл. 2025 г. |
30Наблюдать | CVE-2023-5359Proof of concept | W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintextboldgrid · w3 total cache · CWE-200 | Высокая7,5 | — | 0,8 % | 24 сент. 2024 г. |
30Наблюдать | CVE-2024-24869Эксплойта нет | WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerabilityboldgrid · total upkeep · CWE-22 | Высокая7,5 | — | 0,7 % | 17 мая 2024 г. |
28Наблюдать | CVE-2024-9461Эксплойта нет | Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settingsboldgrid · total upkeep · CWE-78 | Высокая7,2 | — | 1,0 % | 26 нояб. 2024 г. |
28Наблюдать | CVE-2025-2257Эксплойта нет | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injectionboldgrid · total upkeep · CWE-78 | Высокая7,2 | — | 0,9 % | 26 мар. 2025 г. |
27Наблюдать | CVE-2014-9414Эксплойта нет | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct crossboldgrid · w3 total cache · CWE-352 | Средняя6,8 | — | 1,4 % | 24 дек. 2014 г. |
26Наблюдать | CVE-2025-0859Эксплойта нет | Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Functionboldgrid · post and page builder · CWE-22 | Средняя6,5 | — | 0,7 % | 6 февр. 2025 г. |
26Наблюдать | CVE-2024-13907Эксплойта нет | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgeryboldgrid · total upkeep · CWE-918 | Средняя6,5 | — | 0,5 % | 27 февр. 2025 г. |
25Наблюдать | CVE-2021-24452Proof of concept | W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)boldgrid · w3 total cache · CWE-79 | Средняя6,1 | — | 1,9 % | 19 июл. 2021 г. |
25Наблюдать | CVE-2021-24436Proof of concept | W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)boldgrid · w3 total cache · CWE-79 | Средняя6,1 | — | 1,9 % | 19 июл. 2021 г. |
21Наблюдать | CVE-2024-12006Эксплойта нет | W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivationboldgrid · w3 total cache · CWE-862 | Средняя5,3 | — | 0,5 % | 14 янв. 2025 г. |
21Наблюдать | CVE-2024-2950Эксплойта нет | BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposureboldgrid · easy seo · CWE-200 | Средняя5,3 | — | 0,5 % | 6 апр. 2024 г. |
21Наблюдать | CVE-2024-6848Эксплойта нет | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Uploadboldgrid · post and page builder · CWE-79 | Средняя5,4 | — | 0,5 % | 20 июл. 2024 г. |
21Наблюдать | CVE-2024-2888Эксплойта нет | WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerabilityboldgrid · post and page builder · CWE-79 | Средняя5,4 | — | 0,3 % | 26 мар. 2024 г. |
21Наблюдать | CVE-2025-22759Эксплойта нет | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerabilityboldgrid · post and page builder by boldgrid - visual drag and drop editor · CWE-79 | Средняя5,4 | — | 0,3 % | 15 янв. 2025 г. |
21Наблюдать | CVE-2024-4400Эксплойта нет | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scriptingboldgrid · post and page builder · CWE-79 | Средняя5,4 | — | 0,3 % | 16 мая 2024 г. |
19Наблюдать | CVE-2021-24427Эксплойта нет | W3 Total Cache < 2.1.3 - Authenticated Stored XSSboldgrid · w3 total cache · CWE-79 | Средняя4,8 | — | 0,6 % | 12 июл. 2021 г. |
- CVE-2013-201061На этой неделе
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 74 %automattic · wp super cache12 февр. 2020 г.
- CVE-2019-671536Наблюдать
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL fie
ВысокаяCVSS 7,5Proof of conceptEPSS 19 %boldgrid · w3 total cache1 апр. 2019 г.
- CVE-2024-1236535Наблюдать
W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery
ВысокаяCVSS 8,5Proof of conceptEPSS 2 %boldgrid · w3 total cache14 янв. 2025 г.
- CVE-2023-2548035Наблюдать
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %boldgrid · post and page builder6 окт. 2023 г.
- CVE-2012-607732Наблюдать
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %boldgrid · w3 total cache22 нояб. 2019 г.
- CVE-2012-607831Наблюдать
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %boldgrid · w3 total cache22 нояб. 2019 г.
- CVE-2024-1200831Наблюдать
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %boldgrid · w3 total cache14 янв. 2025 г.
- CVE-2012-607931Наблюдать
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %boldgrid · w3 total cache22 нояб. 2019 г.
- CVE-2020-3684830Наблюдать
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
ВысокаяCVSS 7,5Готовый эксплойтEPSS 2 %boldgrid · total upkeep12 июл. 2025 г.
- CVE-2023-535930Наблюдать
W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %boldgrid · w3 total cache24 сент. 2024 г.
- CVE-2024-2486930Наблюдать
WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %boldgrid · total upkeep17 мая 2024 г.
- CVE-2024-946128Наблюдать
Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %boldgrid · total upkeep26 нояб. 2024 г.
- CVE-2025-225728Наблюдать
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %boldgrid · total upkeep26 мар. 2025 г.
- CVE-2014-941427Наблюдать
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross
СредняяCVSS 6,8Эксплойта нетEPSS 1 %boldgrid · w3 total cache24 дек. 2014 г.
- CVE-2025-085926Наблюдать
Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function
СредняяCVSS 6,5Эксплойта нетEPSS 1 %boldgrid · post and page builder6 февр. 2025 г.
- CVE-2024-1390726Наблюдать
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery
СредняяCVSS 6,5Эксплойта нетEPSS 0 %boldgrid · total upkeep27 февр. 2025 г.
- CVE-2021-2445225Наблюдать
W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)
СредняяCVSS 6,1Proof of conceptEPSS 2 %boldgrid · w3 total cache19 июл. 2021 г.
- CVE-2021-2443625Наблюдать
W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)
СредняяCVSS 6,1Proof of conceptEPSS 2 %boldgrid · w3 total cache19 июл. 2021 г.
- CVE-2024-1200621Наблюдать
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
СредняяCVSS 5,3Эксплойта нетEPSS 1 %boldgrid · w3 total cache14 янв. 2025 г.
- CVE-2024-295021Наблюдать
BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 1 %boldgrid · easy seo6 апр. 2024 г.
- CVE-2024-684821Наблюдать
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload
СредняяCVSS 5,4Эксплойта нетEPSS 0 %boldgrid · post and page builder20 июл. 2024 г.
- CVE-2024-288821Наблюдать
WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %boldgrid · post and page builder26 мар. 2024 г.
- CVE-2025-2275921Наблюдать
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %boldgrid · post and page builder by boldgrid - visual drag and drop editor15 янв. 2025 г.
- CVE-2024-440021Наблюдать
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %boldgrid · post and page builder16 мая 2024 г.
- CVE-2021-2442719Наблюдать
W3 Total Cache < 2.1.3 - Authenticated Stored XSS
СредняяCVSS 4,8Эксплойта нетEPSS 1 %boldgrid · w3 total cache12 июл. 2021 г.