hashthemes kayıtları
hashthemes üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %10
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-284 Improper Access Control1
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2024-5084Silahlaştırılmış | Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Executionhashthemes · hash form · CWE-434 | Kritik9,8 | — | %50,7 | 23 May 2024 |
39İzleyin | CVE-2024-5085İstismar yok | Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injectionhashthemes · hash form · CWE-502 | Kritik9,8 | — | %0,8 | 23 May 2024 |
32İzleyin | CVE-2021-39333İstismar yok | Hashthemes Demo Importer <= 1.1.1 Improper Access Control Allowing Content Deletionhashthemes · hashthemes demo importer · CWE-284 | Yüksek8,1 | — | %1,1 | 1 Kas 2021 |
26İzleyin | CVE-2025-22296İstismar yok | WordPress Hash Elements plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerabilityhashthemes · hash elements · CWE-79 | Orta6,5 | — | %0,2 | 7 Oca 2025 |
24İzleyin | CVE-2024-9417İstismar yok | Hash Form - Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Uploadhashthemes · hash form · CWE-434 | Orta6,1 | — | %0,4 | 5 Eki 2024 |
21İzleyin | CVE-2024-10802İstismar yok | Hash Elements <= 1.4.7 - Missing Authorization to Unauthenticated Draft Post Title Exposurehashthemes · hash elements · CWE-862 | Orta5,3 | — | %0,6 | 13 Kas 2024 |
21İzleyin | CVE-2024-30426İstismar yok | WordPress Hash Elements plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerabilityhashthemes · hash elements · CWE-79 | Orta5,4 | — | %0,3 | 29 Mar 2024 |
21İzleyin | CVE-2024-5177İstismar yok | Hash Elements <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter in Multiple Widgetshashthemes · hash elements · CWE-79 | Orta5,4 | — | %0,3 | 23 May 2024 |
17İzleyin | CVE-2024-1771İstismar yok | Total <= 2.1.59 - Missing Authorization to Authenticated (Subscriber+) Sections Updatehashthemes · total · CWE-862 | Orta4,3 | — | %0,4 | 6 Mar 2024 |
17İzleyin | CVE-2024-12201İstismar yok | Hash Form <= 1.2.1 - Missing Authorization to Authenticated (Contributor+) Form Style Creationhashthemes · hash form · CWE-862 | Orta4,3 | — | %0,4 | 12 Ara 2024 |
- CVE-2024-508454Planlayın
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
KritikCVSS 9,8SilahlaştırılmışEPSS %51hashthemes · hash form23 May 2024
- CVE-2024-508539İzleyin
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %1hashthemes · hash form23 May 2024
- CVE-2021-3933332İzleyin
Hashthemes Demo Importer <= 1.1.1 Improper Access Control Allowing Content Deletion
YüksekCVSS 8,1İstismar yokEPSS %1hashthemes · hashthemes demo importer1 Kas 2021
- CVE-2025-2229626İzleyin
WordPress Hash Elements plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0hashthemes · hash elements7 Oca 2025
- CVE-2024-941724İzleyin
Hash Form - Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Upload
OrtaCVSS 6,1İstismar yokEPSS %0hashthemes · hash form5 Eki 2024
- CVE-2024-1080221İzleyin
Hash Elements <= 1.4.7 - Missing Authorization to Unauthenticated Draft Post Title Exposure
OrtaCVSS 5,3İstismar yokEPSS %1hashthemes · hash elements13 Kas 2024
- CVE-2024-3042621İzleyin
WordPress Hash Elements plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0hashthemes · hash elements29 Mar 2024
- CVE-2024-517721İzleyin
Hash Elements <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter in Multiple Widgets
OrtaCVSS 5,4İstismar yokEPSS %0hashthemes · hash elements23 May 2024
- CVE-2024-177117İzleyin
Total <= 2.1.59 - Missing Authorization to Authenticated (Subscriber+) Sections Update
OrtaCVSS 4,3İstismar yokEPSS %0hashthemes · total6 Mar 2024
- CVE-2024-1220117İzleyin
Hash Form <= 1.2.1 - Missing Authorization to Authenticated (Contributor+) Form Style Creation
OrtaCVSS 4,3İstismar yokEPSS %0hashthemes · hash form12 Ara 2024