Записи POSIMYTH
42 опубликованных записей вендора posimyth.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 23,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-862 Missing Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
42 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2021-24175Proof of concept | The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypassposimyth · the plus addons for elementor · CWE-287 | Критическая9,8 | — | 14,5 % | 5 апр. 2021 г. |
40В плане | CVE-2021-24949Эксплойта нет | The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injectionposimyth · the plus addons for elementor · CWE-89 | Критическая9,8 | — | 1,7 % | 10 янв. 2022 г. |
39Наблюдать | CVE-2023-45657Proof of concept | WordPress Nexter Theme <= 2.0.3 is vulnerable to SQL Injectionposimyth · nexter · CWE-89 | Критическая9,8 | — | 1,3 % | 6 нояб. 2023 г. |
39Наблюдать | CVE-2023-47178Эксплойта нет | WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerabilityposimyth · the plus addons for elementor · CWE-22 | Критическая9,8 | — | 0,6 % | 17 мая 2024 г. |
35Наблюдать | CVE-2021-4331Эксплойта нет | The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalationposimyth · the plus addons for elementor · CWE-862 | Высокая8,8 | — | 0,9 % | 7 мар. 2023 г. |
35Наблюдать | CVE-2024-5455Эксплойта нет | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusionposimyth · the plus addons for elementor · CWE-98 | Высокая8,8 | — | 0,6 % | 21 июн. 2024 г. |
35Наблюдать | CVE-2024-2203Эксплойта нет | The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widgetposimyth · the plus addons for elementor · CWE-22 | Высокая8,8 | — | 0,6 % | 26 мар. 2024 г. |
35Наблюдать | CVE-2024-43932Эксплойта нет | WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerabilityposimyth · the plus addons for elementor · CWE-862 | Высокая8,8 | — | 0,6 % | 1 нояб. 2024 г. |
35Наблюдать | CVE-2024-33572Эксплойта нет | WordPress Nexter Blocks plugin <= 3.2.5 - Broken Access Control vulnerabilityposimyth · nexter blocks · CWE-862 | Высокая8,8 | — | 0,4 % | 9 июн. 2024 г. |
31Наблюдать | CVE-2021-24948Эксплойта нет | The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosureposimyth · the plus addons for elementor · CWE-200 | Высокая7,5 | — | 1,8 % | 10 янв. 2022 г. |
28Наблюдать | CVE-2023-45751Эксплойта нет | WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Remote Code Execution (RCE)posimyth · nexter extension · CWE-94 | Высокая7,2 | — | 0,6 % | 29 дек. 2023 г. |
26Наблюдать | CVE-2021-4332Эксплойта нет | The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Readposimyth · the plus addons for elementor · CWE-73 | Средняя6,5 | — | 0,8 % | 7 мар. 2023 г. |
25Наблюдать | CVE-2021-24351Proof of concept | The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)posimyth · the plus addons for elementor · CWE-79 | Средняя6,1 | — | 2,5 % | 14 июн. 2021 г. |
25Наблюдать | CVE-2021-24358Proof of concept | The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirectposimyth · the plus addons for elementor · CWE-601 | Средняя6,1 | — | 2,3 % | 14 июн. 2021 г. |
25Наблюдать | CVE-2024-2210Эксплойта нет | The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listingposimyth · the plus addons for elementor · CWE-22 | Средняя6,4 | — | 0,5 % | 26 мар. 2024 г. |
24Наблюдать | CVE-2023-45750Эксплойта нет | WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)posimyth · nexter extension · CWE-79 | Средняя6,1 | — | 0,4 % | 25 окт. 2023 г. |
24Наблюдать | CVE-2024-5344Эксплойта нет | The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widgetposimyth · the plus addons for elementor · CWE-79 | Средняя6,1 | — | 0,3 % | 20 июн. 2024 г. |
21Наблюдать | CVE-2021-24359Эксплойта нет | The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sendingposimyth · the plus addons for elementor · CWE-284 | Средняя5,3 | — | 1,1 % | 14 июн. 2021 г. |
21Наблюдать | CVE-2024-4484Эксплойта нет | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scriposimyth · the plus addons for elementor · CWE-79 | Средняя5,4 | — | 0,7 % | 24 мая 2024 г. |
21Наблюдать | CVE-2021-24266Эксплойта нет | The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Contributor+ Stored XSSposimyth · the plus addons for elementor page builder lite · CWE-79 | Средняя5,4 | — | 0,6 % | 5 мая 2021 г. |
21Наблюдать | CVE-2024-0445Эксплойта нет | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scriptingposimyth · the plus addons for elementor · CWE-79 | Средняя5,4 | — | 0,5 % | 14 мая 2024 г. |
21Наблюдать | CVE-2024-3199Эксплойта нет | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widgetposimyth · the plus addons for elementor · CWE-79 | Средняя5,4 | — | 0,5 % | 2 мая 2024 г. |
21Наблюдать | CVE-2024-3197Эксплойта нет | The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributesposimyth · the plus addons for elementor · CWE-79 | Средняя5,4 | — | 0,4 % | 2 мая 2024 г. |
21Наблюдать | CVE-2024-11829Эксплойта нет | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scriposimyth · the plus addons for elementor · CWE-79 | Средняя5,4 | — | 0,4 % | 1 февр. 2025 г. |
21Наблюдать | CVE-2024-3718Эксплойта нет | The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricposimyth · the plus addons for elementor · CWE-79 | Средняя5,4 | — | 0,4 % | 24 мая 2024 г. |
- CVE-2021-2417543В плане
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
КритическаяCVSS 9,8Proof of conceptEPSS 14 %posimyth · the plus addons for elementor5 апр. 2021 г.
- CVE-2021-2494940В плане
The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %posimyth · the plus addons for elementor10 янв. 2022 г.
- CVE-2023-4565739Наблюдать
WordPress Nexter Theme <= 2.0.3 is vulnerable to SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 1 %posimyth · nexter6 нояб. 2023 г.
- CVE-2023-4717839Наблюдать
WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor17 мая 2024 г.
- CVE-2021-433135Наблюдать
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor7 мар. 2023 г.
- CVE-2024-545535Наблюдать
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor21 июн. 2024 г.
- CVE-2024-220335Наблюдать
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Clients Widget
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor26 мар. 2024 г.
- CVE-2024-4393235Наблюдать
WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor1 нояб. 2024 г.
- CVE-2024-3357235Наблюдать
WordPress Nexter Blocks plugin <= 3.2.5 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %posimyth · nexter blocks9 июн. 2024 г.
- CVE-2021-2494831Наблюдать
The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %posimyth · the plus addons for elementor10 янв. 2022 г.
- CVE-2023-4575128Наблюдать
WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Remote Code Execution (RCE)
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %posimyth · nexter extension29 дек. 2023 г.
- CVE-2021-433226Наблюдать
The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read
СредняяCVSS 6,5Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor7 мар. 2023 г.
- CVE-2021-2435125Наблюдать
The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Proof of conceptEPSS 2 %posimyth · the plus addons for elementor14 июн. 2021 г.
- CVE-2021-2435825Наблюдать
The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect
СредняяCVSS 6,1Proof of conceptEPSS 2 %posimyth · the plus addons for elementor14 июн. 2021 г.
- CVE-2024-221025Наблюдать
The Plus Addons for Elementor <= 5.4.1 - Authenticated (Contributor+) Local File Inclusion via Team Member Listing
СредняяCVSS 6,4Эксплойта нетEPSS 0 %posimyth · the plus addons for elementor26 мар. 2024 г.
- CVE-2023-4575024Наблюдать
WordPress Nexter Extension Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %posimyth · nexter extension25 окт. 2023 г.
- CVE-2024-534424Наблюдать
The Plus Addons for Elementor Page Builder <= 5.5.6 - Reflected Cross-Site Scripting via WP Login and Register Widget
СредняяCVSS 6,1Эксплойта нетEPSS 0 %posimyth · the plus addons for elementor20 июн. 2024 г.
- CVE-2021-2435921Наблюдать
The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending
СредняяCVSS 5,3Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor14 июн. 2021 г.
- CVE-2024-448421Наблюдать
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scri
СредняяCVSS 5,4Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor24 мая 2024 г.
- CVE-2021-2426621Наблюдать
The Plus Addons for Elementor Page Builder Lite < 2.0.6 - Contributor+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor page builder lite5 мая 2021 г.
- CVE-2024-044521Наблюдать
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor14 мая 2024 г.
- CVE-2024-319921Наблюдать
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget
СредняяCVSS 5,4Эксплойта нетEPSS 1 %posimyth · the plus addons for elementor2 мая 2024 г.
- CVE-2024-319721Наблюдать
The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes
СредняяCVSS 5,4Эксплойта нетEPSS 0 %posimyth · the plus addons for elementor2 мая 2024 г.
- CVE-2024-1182921Наблюдать
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scri
СредняяCVSS 5,4Эксплойта нетEPSS 0 %posimyth · the plus addons for elementor1 февр. 2025 г.
- CVE-2024-371821Наблюдать
The Plus Addons for Elementor <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pric
СредняяCVSS 5,4Эксплойта нетEPSS 0 %posimyth · the plus addons for elementor24 мая 2024 г.