edmonsoft records
8 published records for vendor edmonsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-29423No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Pro Features Lock Bypass vulnerabilityedmonsoft · countdown builder · CWE-264 | Critical9.8 | — | 1.1% | May 6, 2022 |
28Monitor | CVE-2023-3392No exploit | Read More & Accordion < 3.2.7 - Admin+ PHP Object Injectionedmonsoft · read more \& accordion · CWE-502 | High7.2 | — | 1.0% | Oct 16, 2023 |
24Monitor | CVE-2022-0601No exploit | Countdown & Clock < 2.2.9 - Reflected Cross-Site Scriptingedmonsoft · countdown\, coming soon\, maintenance - countdown \& clock · CWE-79 | Medium6.1 | — | 0.9% | Mar 14, 2022 |
24Monitor | CVE-2022-29421No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Reflected Cross-Site Scripting (XSS) vulnerabilityedmonsoft · countdown builder · CWE-79 | Medium6.1 | — | 0.8% | May 6, 2022 |
21Monitor | CVE-2024-2017No exploit | Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injectionedmonsoft · countdown builder · CWE-862 | Medium5.4 | — | 0.3% | Jun 5, 2024 |
19Monitor | CVE-2022-29422No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitiesedmonsoft · countdown builder · CWE-79 | Medium4.8 | — | 0.6% | May 6, 2022 |
19Monitor | CVE-2022-29420No exploit | WordPress Countdown & Clock plugin <= 2.3.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityedmonsoft · countdown builder · CWE-79 | Medium4.8 | — | 0.4% | May 6, 2022 |
17Monitor | CVE-2024-13639No exploit | Read More & Accordion <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Read More' Post Deletionedmonsoft · read more \& accordion · CWE-862 | Medium4.3 | — | 0.3% | Feb 13, 2025 |
- CVE-2022-2942339Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Pro Features Lock Bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 1%edmonsoft · countdown builderMay 6, 2022
- CVE-2023-339228Monitor
Read More & Accordion < 3.2.7 - Admin+ PHP Object Injection
HighCVSS 7.2No exploitEPSS 1%edmonsoft · read more \& accordionOct 16, 2023
- CVE-2022-060124Monitor
Countdown & Clock < 2.2.9 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%edmonsoft · countdown\, coming soon\, maintenance - countdown \& clockMar 14, 2022
- CVE-2022-2942124Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%edmonsoft · countdown builderMay 6, 2022
- CVE-2024-201721Monitor
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection
MediumCVSS 5.4No exploitEPSS 0%edmonsoft · countdown builderJun 5, 2024
- CVE-2022-2942219Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
MediumCVSS 4.8No exploitEPSS 1%edmonsoft · countdown builderMay 6, 2022
- CVE-2022-2942019Monitor
WordPress Countdown & Clock plugin <= 2.3.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%edmonsoft · countdown builderMay 6, 2022
- CVE-2024-1363917Monitor
Read More & Accordion <= 3.4.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Read More' Post Deletion
MediumCVSS 4.3No exploitEPSS 0%edmonsoft · read more \& accordionFeb 13, 2025