BoxyStudio kayıtları
boxystudio üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %23,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2022-3900İstismar yok | Cooked Pro < 1.7.5.7 - Unauthenticated PHP Object Injectionboxystudio · cooked · CWE-502 | Kritik9,8 | — | %19,0 | 12 Ara 2022 |
40Planlayın | CVE-2024-49291İstismar yok | WordPress Cooked Pro plugin < 1.8.0 - Unauthenticated Arbitrary File Upload vulnerabilitygora tech llc · cooked pro · CWE-434 | Kritik10,0 | — | %0,5 | 17 Eki 2024 |
35İzleyin | CVE-2024-39679İstismar yok | WordPress Cooked Plugin - Cross-Site Request Forgery to Recipe Template Resetboxystudio · cooked · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2024 |
35İzleyin | CVE-2024-39678İstismar yok | WordPress Cooked Plugin - Cross-Site Request Forgery to Get Recipe IDsboxystudio · cooked · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2024 |
35İzleyin | CVE-2024-39680İstismar yok | WordPress Cooked Plugin - Cross-Site Request Forgery to Default Recipe Template Saveboxystudio · cooked · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2024 |
35İzleyin | CVE-2024-39681İstismar yok | WordPress Cooked Plugin - Cross-Site Request Forgery to Apply Template to All Recipesboxystudio · cooked · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2024 |
35İzleyin | CVE-2024-49290İstismar yok | WordPress Cooked Pro plugin < 1.8.0 - Cross Site Request Forgery (CSRF) vulnerabilityboxystudio · cooked · CWE-352 | Yüksek8,8 | — | %0,2 | 20 Eki 2024 |
30İzleyin | CVE-2022-36399İstismar yok | WordPress Booked Plugin < 2.4.4 is vulnerable to Sensitive Data Exposureboxystudio · booked · CWE-200 | Yüksek7,5 | — | %0,5 | 28 Ara 2023 |
25İzleyin | CVE-2021-24233İstismar yok | Cooked Pro < 1.7.5.6 - Unauthenticated Reflected Cross Site Scripting (XSS)boxystudio · cooked · CWE-79 | Orta6,1 | — | %1,7 | 22 Nis 2021 |
21İzleyin | CVE-2024-37308İstismar yok | WordPress Cooked Plugin - Authenticated (Contributor+) Persistent Cross-Site Scripting Vulnerabilityboxystudio · cooked · CWE-79 | Orta5,4 | — | %0,4 | 13 Haz 2024 |
21İzleyin | CVE-2024-41816İstismar yok | WordPress Cooked Plugin Persistent Cross-Site Scripting via Shortcodeboxystudio · cooked · CWE-79 | Orta5,4 | — | %0,4 | 5 Ağu 2024 |
21İzleyin | CVE-2024-39682İstismar yok | WordPress Cooked Plugin - Authenticated (Contributor+) HTML Injection via Recipe Excerptboxystudio · cooked · CWE-116 | Orta5,4 | — | %0,4 | 17 Tem 2024 |
21İzleyin | CVE-2023-44477İstismar yok | WordPress Cooked Plugin <= 1.7.13 is vulnerable to Cross Site Scripting (XSS)boxystudio · cooked · CWE-79 | Orta5,4 | — | %0,3 | 2 Eki 2023 |
- CVE-2022-390045Planlayın
Cooked Pro < 1.7.5.7 - Unauthenticated PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %19boxystudio · cooked12 Ara 2022
- CVE-2024-4929140Planlayın
WordPress Cooked Pro plugin < 1.8.0 - Unauthenticated Arbitrary File Upload vulnerability
KritikCVSS 10,0İstismar yokEPSS %1gora tech llc · cooked pro17 Eki 2024
- CVE-2024-3967935İzleyin
WordPress Cooked Plugin - Cross-Site Request Forgery to Recipe Template Reset
YüksekCVSS 8,8İstismar yokEPSS %0boxystudio · cooked17 Tem 2024
- CVE-2024-3967835İzleyin
WordPress Cooked Plugin - Cross-Site Request Forgery to Get Recipe IDs
YüksekCVSS 8,8İstismar yokEPSS %0boxystudio · cooked17 Tem 2024
- CVE-2024-3968035İzleyin
WordPress Cooked Plugin - Cross-Site Request Forgery to Default Recipe Template Save
YüksekCVSS 8,8İstismar yokEPSS %0boxystudio · cooked17 Tem 2024
- CVE-2024-3968135İzleyin
WordPress Cooked Plugin - Cross-Site Request Forgery to Apply Template to All Recipes
YüksekCVSS 8,8İstismar yokEPSS %0boxystudio · cooked17 Tem 2024
- CVE-2024-4929035İzleyin
WordPress Cooked Pro plugin < 1.8.0 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0boxystudio · cooked20 Eki 2024
- CVE-2022-3639930İzleyin
WordPress Booked Plugin < 2.4.4 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5İstismar yokEPSS %1boxystudio · booked28 Ara 2023
- CVE-2021-2423325İzleyin
Cooked Pro < 1.7.5.6 - Unauthenticated Reflected Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %2boxystudio · cooked22 Nis 2021
- CVE-2024-3730821İzleyin
WordPress Cooked Plugin - Authenticated (Contributor+) Persistent Cross-Site Scripting Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0boxystudio · cooked13 Haz 2024
- CVE-2024-4181621İzleyin
WordPress Cooked Plugin Persistent Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0boxystudio · cooked5 Ağu 2024
- CVE-2024-3968221İzleyin
WordPress Cooked Plugin - Authenticated (Contributor+) HTML Injection via Recipe Excerpt
OrtaCVSS 5,4İstismar yokEPSS %0boxystudio · cooked17 Tem 2024
- CVE-2023-4447721İzleyin
WordPress Cooked Plugin <= 1.7.13 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0boxystudio · cooked2 Eki 2023