ConveyThis records
2 published records for vendor conveythis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2023-6811No exploit | Language Translate Widget for WordPress – ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_keyconveythis · translate wordpress websites globally with conveythis translate · CWE-79 | High7.2 | — | 0.4% | Apr 10, 2024 |
21Monitor | CVE-2024-38792No exploit | WordPress ConveyThis Translate plugin <= 234 - Non-arbitrary Options Update vulnerabilityconveythis translate team · language translate widget for wordpress – conveythis · CWE-862 | Medium5.3 | — | 0.4% | Nov 1, 2024 |
- CVE-2023-681128Monitor
Language Translate Widget for WordPress – ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_key
HighCVSS 7.2No exploitEPSS 0%conveythis · translate wordpress websites globally with conveythis translateApr 10, 2024
- CVE-2024-3879221Monitor
WordPress ConveyThis Translate plugin <= 234 - Non-arbitrary Options Update vulnerability
MediumCVSS 5.3No exploitEPSS 0%conveythis translate team · language translate widget for wordpress – conveythisNov 1, 2024