coolplugins kayıtları
coolplugins üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-36681İstismar yok | WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerabilitycoolplugins · cryptocurrency widgets · CWE-862 | Kritik9,8 | — | %0,9 | 13 Ara 2024 |
39İzleyin | CVE-2024-53739İstismar yok | WordPress Cryptocurrency Widgets For Elementor plugin <= 1.6.4 - Local File Inclusion vulnerabilitycoolplugins · cryptocurrency widgets for elementor · CWE-98 | Kritik9,8 | — | %0,7 | 30 Kas 2024 |
35İzleyin | CVE-2022-4950İstismar yok | Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activationcoolplugins · cool timeline · CWE-862 | Yüksek8,8 | — | %1,4 | 6 Haz 2023 |
35İzleyin | CVE-2021-4349İstismar yok | Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgerycoolplugins · process steps template designer · CWE-352 | Yüksek8,8 | — | %0,6 | 6 Haz 2023 |
35İzleyin | CVE-2023-52142İstismar yok | WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injectioncoolplugins · events shortcodes for the events calendar · CWE-89 | Yüksek8,8 | — | %0,5 | 8 Oca 2024 |
30İzleyin | CVE-2024-0709İstismar yok | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in coolplugins · cryptocurrency widgets · CWE-89 | Yüksek7,5 | — | %0,9 | 5 Şub 2024 |
24İzleyin | CVE-2024-43304İstismar yok | WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerabilitycoolplugins · cryptocurrency widgets · CWE-79 | Orta6,1 | — | %0,3 | 18 Ağu 2024 |
21İzleyin | CVE-2024-0977İstismar yok | Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scriptingcoolplugins · timeline widget for elementor · CWE-79 | Orta5,4 | — | %0,3 | 7 Şub 2024 |
21İzleyin | CVE-2024-52354İstismar yok | WordPress Web Stories Widgets For Elementor plugin <= 1.1 - Cross Site Scripting (XSS) vulnerabilitycoolplugins · web stories widgets for elementor · CWE-79 | Orta5,4 | — | %0,3 | 11 Kas 2024 |
18İzleyin | CVE-2024-27953İstismar yok | WordPress Cryptocurrency Widgets – Price Ticker & Coins List Plugin <= 2.6.8 is vulnerable to Broken Access Controlcoolplugins · cryptocurrency widgets · CWE-862 | Orta4,7 | — | %0,4 | 13 Mar 2024 |
17İzleyin | CVE-2020-36738İstismar yok | Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery Bypasscoolplugins · cool timeline · CWE-352 | Orta4,3 | — | %0,5 | 1 Tem 2023 |
17İzleyin | CVE-2021-4413İstismar yok | Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery Bypasscoolplugins · process steps template designer · CWE-352 | Orta4,3 | — | %0,4 | 12 Tem 2023 |
- CVE-2023-3668139İzleyin
WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %1coolplugins · cryptocurrency widgets13 Ara 2024
- CVE-2024-5373939İzleyin
WordPress Cryptocurrency Widgets For Elementor plugin <= 1.6.4 - Local File Inclusion vulnerability
KritikCVSS 9,8İstismar yokEPSS %1coolplugins · cryptocurrency widgets for elementor30 Kas 2024
- CVE-2022-495035İzleyin
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation
YüksekCVSS 8,8İstismar yokEPSS %1coolplugins · cool timeline6 Haz 2023
- CVE-2021-434935İzleyin
Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery
YüksekCVSS 8,8İstismar yokEPSS %1coolplugins · process steps template designer6 Haz 2023
- CVE-2023-5214235İzleyin
WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1coolplugins · events shortcodes for the events calendar8 Oca 2024
- CVE-2024-070930İzleyin
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in
YüksekCVSS 7,5İstismar yokEPSS %1coolplugins · cryptocurrency widgets5 Şub 2024
- CVE-2024-4330424İzleyin
WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0coolplugins · cryptocurrency widgets18 Ağu 2024
- CVE-2024-097721İzleyin
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0coolplugins · timeline widget for elementor7 Şub 2024
- CVE-2024-5235421İzleyin
WordPress Web Stories Widgets For Elementor plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0coolplugins · web stories widgets for elementor11 Kas 2024
- CVE-2024-2795318İzleyin
WordPress Cryptocurrency Widgets – Price Ticker & Coins List Plugin <= 2.6.8 is vulnerable to Broken Access Control
OrtaCVSS 4,7İstismar yokEPSS %0coolplugins · cryptocurrency widgets13 Mar 2024
- CVE-2020-3673817İzleyin
Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery Bypass
OrtaCVSS 4,3İstismar yokEPSS %0coolplugins · cool timeline1 Tem 2023
- CVE-2021-441317İzleyin
Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery Bypass
OrtaCVSS 4,3İstismar yokEPSS %0coolplugins · process steps template designer12 Tem 2023