premio records
23 published records for vendor premio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 43.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-862 Missing Authorization1
- CWE-863 Incorrect Authorization1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-11429No exploit | Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusionpremio · stars testimonials — responsive reviews & star ratings · CWE-98 | High8.8 | — | 0.7% | Dec 5, 2024 |
28Monitor | CVE-2023-0487No exploit | My Sticky Elements < 2.0.9 - Admin+ SQLipremio · my sticky elements · CWE-89 | High7.2 | — | 1.5% | Feb 27, 2023 |
28Monitor | CVE-2022-3858No exploit | Chaty < 3.0.3 - Admin+ SQLipremio · chaty · CWE-89 | High7.2 | — | 1.0% | Dec 5, 2022 |
28Monitor | CVE-2023-40204No exploit | WordPress Folders Plugin <= 2.9.2 is vulnerable to Arbitrary File Uploadpremio · folders · CWE-434 | High7.2 | — | 0.8% | Dec 20, 2023 |
25Monitor | CVE-2021-25016Proof of concept | Chaty < 2.8.3 - Reflected Cross-Site Scriptingpremio · chaty · CWE-79 | Medium6.1 | — | 1.8% | Jan 3, 2022 |
24Monitor | CVE-2023-25019No exploit | WordPress Chaty Plugin <= 3.0.9 is vulnerable to Cross Site Scripting (XSS)premio · chaty · CWE-79 | Medium6.1 | — | 0.4% | Aug 30, 2023 |
21Monitor | CVE-2022-0148Proof of concept | All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)premio · mystickyelements · CWE-79 | Medium5.4 | — | 1.6% | Feb 7, 2022 |
21Monitor | CVE-2023-5509No exploit | myStickymenu < 2.6.5 - Subscriber+ Arbitrary Form Leads Deletionpremio · mystickymenu · CWE-863 | Medium5.4 | — | 0.5% | Nov 20, 2023 |
21Monitor | CVE-2023-51362No exploit | WordPress myStickyElements plugin <= 2.1.3 - Broken Access Control vulnerabilitypremio · my sticky elements · CWE-862 | Medium5.3 | — | 0.5% | Dec 9, 2024 |
21Monitor | CVE-2024-7317No exploit | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting viapremio · folders · CWE-79 | Medium5.4 | — | 0.4% | Aug 6, 2024 |
21Monitor | CVE-2025-1450No exploit | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributorpremio · floating chat widget · CWE-79 | Medium5.4 | — | 0.3% | Feb 27, 2025 |
19Monitor | CVE-2021-24425No exploit | myStickymenu < 2.5.2 - Authenticated Stored XSSpremio · mystickymenu · CWE-79 | Medium4.8 | — | 0.6% | Aug 2, 2021 |
19Monitor | CVE-2021-36846No exploit | WordPress Chaty plugin <= 2.8.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitypremio · chaty · CWE-79 | Medium4.8 | — | 0.6% | Apr 11, 2022 |
19Monitor | CVE-2023-3248No exploit | All-in-one Floating Contact Form < 2.1.2 - Admin+ Stored Cross-Site Scriptingpremio · my sticky elements · CWE-79 | Medium4.8 | — | 0.5% | Jul 24, 2023 |
19Monitor | CVE-2023-3245No exploit | Floating Chat Widget < 3.1.2 - Admin+ Stored Cross-Site Scriptingpremio · chaty · CWE-79 | Medium4.8 | — | 0.5% | Jul 17, 2023 |
19Monitor | CVE-2024-4090No exploit | My Sticky Bar < 2.7.2 - Admin+ Stored XSSpremio · my sticky bar · CWE-79 | Medium4.8 | — | 0.5% | Aug 1, 2024 |
19Monitor | CVE-2024-7133No exploit | My Sticky Bar < 2.7.3 - Admin+ Stored XSSpremio · my sticky bar · CWE-79 | Medium4.8 | — | 0.4% | Sep 13, 2024 |
19Monitor | CVE-2024-4149No exploit | Floating Chat Widget < 3.2.3 - Admin+ Stored XSSpremio · floating chat widget · CWE-79 | Medium4.8 | — | 0.4% | Jun 13, 2024 |
19Monitor | CVE-2023-47759No exploit | WordPress Chaty plugin <= 3.1.2 - Cross Site Scripting (XSS) vulnerabilitypremio · chaty · CWE-79 | Medium4.8 | — | 0.4% | Nov 22, 2023 |
19Monitor | CVE-2024-2643No exploit | My Sticky Bar < 2.6.8 - Admin+ Stored XSSpremio · my sticky bar · CWE-79 | Medium4.8 | — | 0.3% | May 15, 2025 |
17Monitor | CVE-2024-2023No exploit | Folders <= 3.0 and Folders Pro <= 3.0.2 - Directory Traversal via handle_folders_file_uploadpremio · folders – unlimited folders to organize media library folder, pages, posts, file manager · CWE-22 | Medium4.3 | — | 0.7% | Jun 14, 2024 |
17Monitor | CVE-2023-7048No exploit | My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposurepremio · my sticky bar · CWE-352 | Medium4.3 | — | 0.2% | Jan 11, 2024 |
15Monitor | CVE-2024-2972No exploit | Floating Chat Widget < 3.1.9 - Editor+ Stored XSSpremio · floating chat widget · CWE-79 | Low3.8 | — | 0.4% | Apr 24, 2024 |
- CVE-2024-1142935Monitor
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%premio · stars testimonials — responsive reviews & star ratingsDec 5, 2024
- CVE-2023-048728Monitor
My Sticky Elements < 2.0.9 - Admin+ SQLi
HighCVSS 7.2No exploitEPSS 1%premio · my sticky elementsFeb 27, 2023
- CVE-2022-385828Monitor
Chaty < 3.0.3 - Admin+ SQLi
HighCVSS 7.2No exploitEPSS 1%premio · chatyDec 5, 2022
- CVE-2023-4020428Monitor
WordPress Folders Plugin <= 2.9.2 is vulnerable to Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%premio · foldersDec 20, 2023
- CVE-2021-2501625Monitor
Chaty < 2.8.3 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 2%premio · chatyJan 3, 2022
- CVE-2023-2501924Monitor
WordPress Chaty Plugin <= 3.0.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%premio · chatyAug 30, 2023
- CVE-2022-014821Monitor
All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
MediumCVSS 5.4Proof of conceptEPSS 2%premio · mystickyelementsFeb 7, 2022
- CVE-2023-550921Monitor
myStickymenu < 2.6.5 - Subscriber+ Arbitrary Form Leads Deletion
MediumCVSS 5.4No exploitEPSS 1%premio · mystickymenuNov 20, 2023
- CVE-2023-5136221Monitor
WordPress myStickyElements plugin <= 2.1.3 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%premio · my sticky elementsDec 9, 2024
- CVE-2024-731721Monitor
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via
MediumCVSS 5.4No exploitEPSS 0%premio · foldersAug 6, 2024
- CVE-2025-145021Monitor
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor
MediumCVSS 5.4No exploitEPSS 0%premio · floating chat widgetFeb 27, 2025
- CVE-2021-2442519Monitor
myStickymenu < 2.5.2 - Authenticated Stored XSS
MediumCVSS 4.8No exploitEPSS 1%premio · mystickymenuAug 2, 2021
- CVE-2021-3684619Monitor
WordPress Chaty plugin <= 2.8.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 1%premio · chatyApr 11, 2022
- CVE-2023-324819Monitor
All-in-one Floating Contact Form < 2.1.2 - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%premio · my sticky elementsJul 24, 2023
- CVE-2023-324519Monitor
Floating Chat Widget < 3.1.2 - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 0%premio · chatyJul 17, 2023
- CVE-2024-409019Monitor
My Sticky Bar < 2.7.2 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%premio · my sticky barAug 1, 2024
- CVE-2024-713319Monitor
My Sticky Bar < 2.7.3 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%premio · my sticky barSep 13, 2024
- CVE-2024-414919Monitor
Floating Chat Widget < 3.2.3 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%premio · floating chat widgetJun 13, 2024
- CVE-2023-4775919Monitor
WordPress Chaty plugin <= 3.1.2 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 4.8No exploitEPSS 0%premio · chatyNov 22, 2023
- CVE-2024-264319Monitor
My Sticky Bar < 2.6.8 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%premio · my sticky barMay 15, 2025
- CVE-2024-202317Monitor
Folders <= 3.0 and Folders Pro <= 3.0.2 - Directory Traversal via handle_folders_file_upload
MediumCVSS 4.3No exploitEPSS 1%premio · folders – unlimited folders to organize media library folder, pages, posts, file managerJun 14, 2024
- CVE-2023-704817Monitor
My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposure
MediumCVSS 4.3No exploitEPSS 0%premio · my sticky barJan 11, 2024
- CVE-2024-297215Monitor
Floating Chat Widget < 3.1.9 - Editor+ Stored XSS
LowCVSS 3.8No exploitEPSS 0%premio · floating chat widgetApr 24, 2024