İçeriğe atla
Noroxi

smackcoders kayıtları

smackcoders üreticisine ait 24 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%4,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

24 kayıt
  • CVE-2016-11000
    40Planlayın

    The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    smackcoders · ultimate exporter20 Eyl 2019

  • CVE-2024-43965
    40Planlayın

    WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    smackcoders · sendgrid29 Ağu 2024

  • CVE-2023-4141
    35İzleyin

    WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution

    YüksekCVSS 8,8İstismar yokEPSS %2

    smackcoders · wp ultimate csv importer3 Ağu 2023

  • CVE-2023-4142
    35İzleyin

    WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution

    YüksekCVSS 8,8İstismar yokEPSS %2

    smackcoders · wp ultimate csv importer3 Ağu 2023

  • CVE-2022-3860
    35İzleyin

    Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi

    YüksekCVSS 8,8İstismar yokEPSS %1

    smackcoders · visual email designer for woocommerce2 Oca 2023

  • CVE-2023-4140
    35İzleyin

    WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation

    YüksekCVSS 8,8İstismar yokEPSS %1

    smackcoders · wp ultimate csv importer3 Ağu 2023

  • CVE-2018-20967
    35İzleyin

    The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

    YüksekCVSS 8,8İstismar yokEPSS %1

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv14 Ağu 2019

  • CVE-2018-20968
    35İzleyin

    The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

    YüksekCVSS 8,8İstismar yokEPSS %1

    smackcoders · ultimate exporter14 Ağu 2019

  • CVE-2015-10125
    35İzleyin

    WP Ultimate CSV Importer Plugin cross-site request forgery

    YüksekCVSS 8,8İstismar yokEPSS %0

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv5 Eki 2023

  • CVE-2023-4139
    30İzleyin

    WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing

    YüksekCVSS 7,5İstismar yokEPSS %1

    smackcoders · wp ultimate csv importer3 Ağu 2023

  • CVE-2023-45066
    30İzleyin

    WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure

    YüksekCVSS 7,5İstismar yokEPSS %1

    smackcoders · export all posts\, products\, orders\, refunds \& users30 Kas 2023

  • CVE-2024-12315
    30İzleyin

    Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory

    YüksekCVSS 7,5İstismar yokEPSS %0

    smackcoders · export all posts\, products\, orders\, refunds \& users12 Şub 2025

  • CVE-2023-2487
    30İzleyin

    WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure

    YüksekCVSS 7,5İstismar yokEPSS %0

    smackcoders · export all posts\, products\, orders\, refunds \& users21 Ara 2023

  • CVE-2022-1977
    28İzleyin

    WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF

    YüksekCVSS 7,2İstismar yokEPSS %1

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv27 Haz 2022

  • CVE-2022-3243
    28İzleyin

    Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi

    YüksekCVSS 7,2İstismar yokEPSS %1

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 Eki 2022

  • CVE-2013-3264
    26İzleyin

    The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2

    OrtaCVSS 6,4İstismar yokEPSS %2

    smackcoders · wp ultimate email marketer plugin5 Kas 2013

  • CVE-2016-10985
    24İzleyin

    The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    smackcoders · echo sign17 Eyl 2019

  • CVE-2016-10984
    24İzleyin

    The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    smackcoders · echo sign17 Eyl 2019

  • CVE-2015-9306
    24İzleyin

    The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv12 Ağu 2019

  • CVE-2022-0360
    19İzleyin

    WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting

    OrtaCVSS 4,8İstismar yokEPSS %1

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv28 Şub 2022

  • CVE-2013-3263
    17İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow

    OrtaCVSS 4,3İstismar yokEPSS %2

    smackcoders · wp ultimate email marketer plugin5 Kas 2013

  • CVE-2024-9364
    17İzleyin

    SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion

    OrtaCVSS 4,3İstismar yokEPSS %0

    smackcoders · sendgrid18 Eki 2024

  • CVE-2025-5692
    17İzleyin

    Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions

    OrtaCVSS 4,3İstismar yokEPSS %0

    smackcoders · lead form data collection to crm1 Tem 2025

  • CVE-2022-3244
    16İzleyin

    Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation

    OrtaCVSS 4,2İstismar yokEPSS %0

    smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 Eki 2022