smackcoders kayıtları
smackcoders üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %4,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-11000İstismar yok | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.smackcoders · ultimate exporter · CWE-89 | Kritik9,8 | — | %2,1 | 20 Eyl 2019 |
40Planlayın | CVE-2024-43965Kavram kanıtı | WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerabilitysmackcoders · sendgrid · CWE-89 | Kritik9,8 | — | %2,0 | 29 Ağu 2024 |
35İzleyin | CVE-2023-4141İstismar yok | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Executionsmackcoders · wp ultimate csv importer · CWE-94 | Yüksek8,8 | — | %1,6 | 3 Ağu 2023 |
35İzleyin | CVE-2023-4142İstismar yok | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Executionsmackcoders · wp ultimate csv importer · CWE-94 | Yüksek8,8 | — | %1,6 | 3 Ağu 2023 |
35İzleyin | CVE-2022-3860İstismar yok | Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLismackcoders · visual email designer for woocommerce · CWE-89 | Yüksek8,8 | — | %0,9 | 2 Oca 2023 |
35İzleyin | CVE-2023-4140İstismar yok | WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalationsmackcoders · wp ultimate csv importer · CWE-269 | Yüksek8,8 | — | %0,8 | 3 Ağu 2023 |
35İzleyin | CVE-2018-20967İstismar yok | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-352 | Yüksek8,8 | — | %0,6 | 14 Ağu 2019 |
35İzleyin | CVE-2018-20968İstismar yok | The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.smackcoders · ultimate exporter · CWE-352 | Yüksek8,8 | — | %0,6 | 14 Ağu 2019 |
35İzleyin | CVE-2015-10125İstismar yok | WP Ultimate CSV Importer Plugin cross-site request forgerysmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-352 | Yüksek8,8 | — | %0,4 | 5 Eki 2023 |
30İzleyin | CVE-2023-4139İstismar yok | WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listingsmackcoders · wp ultimate csv importer · CWE-200 | Yüksek7,5 | — | %0,7 | 3 Ağu 2023 |
30İzleyin | CVE-2023-45066İstismar yok | WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposuresmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-200 | Yüksek7,5 | — | %0,5 | 30 Kas 2023 |
30İzleyin | CVE-2024-12315İstismar yok | Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directorysmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-922 | Yüksek7,5 | — | %0,5 | 12 Şub 2025 |
30İzleyin | CVE-2023-2487İstismar yok | WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposuresmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-200 | Yüksek7,5 | — | %0,5 | 21 Ara 2023 |
28İzleyin | CVE-2022-1977İstismar yok | WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRFsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-918 | Yüksek7,2 | — | %1,3 | 27 Haz 2022 |
28İzleyin | CVE-2022-3243İstismar yok | Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLismackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-89 | Yüksek7,2 | — | %1,1 | 17 Eki 2022 |
26İzleyin | CVE-2013-3264İstismar yok | The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2smackcoders · wp ultimate email marketer plugin · CWE-264 | Orta6,4 | — | %2,1 | 5 Kas 2013 |
24İzleyin | CVE-2016-10985İstismar yok | The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.smackcoders · echo sign · CWE-79 | Orta6,1 | — | %1,4 | 17 Eyl 2019 |
24İzleyin | CVE-2016-10984İstismar yok | The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.smackcoders · echo sign · CWE-79 | Orta6,1 | — | %1,4 | 17 Eyl 2019 |
24İzleyin | CVE-2015-9306İstismar yok | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-79 | Orta6,1 | — | %1,0 | 12 Ağu 2019 |
19İzleyin | CVE-2022-0360İstismar yok | WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scriptingsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-79 | Orta4,8 | — | %0,6 | 28 Şub 2022 |
17İzleyin | CVE-2013-3263İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow smackcoders · wp ultimate email marketer plugin · CWE-79 | Orta4,3 | — | %1,6 | 5 Kas 2013 |
17İzleyin | CVE-2024-9364İstismar yok | SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletionsmackcoders · sendgrid · CWE-862 | Orta4,3 | — | %0,4 | 18 Eki 2024 |
17İzleyin | CVE-2025-5692İstismar yok | Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actionssmackcoders · lead form data collection to crm · CWE-862 | Orta4,3 | — | %0,2 | 1 Tem 2025 |
16İzleyin | CVE-2022-3244İstismar yok | Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisationsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-862 | Orta4,2 | — | %0,4 | 17 Eki 2022 |
- CVE-2016-1100040Planlayın
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
KritikCVSS 9,8İstismar yokEPSS %2smackcoders · ultimate exporter20 Eyl 2019
- CVE-2024-4396540Planlayın
WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %2smackcoders · sendgrid29 Ağu 2024
- CVE-2023-414135İzleyin
WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution
YüksekCVSS 8,8İstismar yokEPSS %2smackcoders · wp ultimate csv importer3 Ağu 2023
- CVE-2023-414235İzleyin
WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution
YüksekCVSS 8,8İstismar yokEPSS %2smackcoders · wp ultimate csv importer3 Ağu 2023
- CVE-2022-386035İzleyin
Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi
YüksekCVSS 8,8İstismar yokEPSS %1smackcoders · visual email designer for woocommerce2 Oca 2023
- CVE-2023-414035İzleyin
WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %1smackcoders · wp ultimate csv importer3 Ağu 2023
- CVE-2018-2096735İzleyin
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv14 Ağu 2019
- CVE-2018-2096835İzleyin
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1smackcoders · ultimate exporter14 Ağu 2019
- CVE-2015-1012535İzleyin
WP Ultimate CSV Importer Plugin cross-site request forgery
YüksekCVSS 8,8İstismar yokEPSS %0smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv5 Eki 2023
- CVE-2023-413930İzleyin
WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing
YüksekCVSS 7,5İstismar yokEPSS %1smackcoders · wp ultimate csv importer3 Ağu 2023
- CVE-2023-4506630İzleyin
WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5İstismar yokEPSS %1smackcoders · export all posts\, products\, orders\, refunds \& users30 Kas 2023
- CVE-2024-1231530İzleyin
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory
YüksekCVSS 7,5İstismar yokEPSS %0smackcoders · export all posts\, products\, orders\, refunds \& users12 Şub 2025
- CVE-2023-248730İzleyin
WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5İstismar yokEPSS %0smackcoders · export all posts\, products\, orders\, refunds \& users21 Ara 2023
- CVE-2022-197728İzleyin
WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF
YüksekCVSS 7,2İstismar yokEPSS %1smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv27 Haz 2022
- CVE-2022-324328İzleyin
Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
YüksekCVSS 7,2İstismar yokEPSS %1smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 Eki 2022
- CVE-2013-326426İzleyin
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2
OrtaCVSS 6,4İstismar yokEPSS %2smackcoders · wp ultimate email marketer plugin5 Kas 2013
- CVE-2016-1098524İzleyin
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
OrtaCVSS 6,1İstismar yokEPSS %1smackcoders · echo sign17 Eyl 2019
- CVE-2016-1098424İzleyin
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
OrtaCVSS 6,1İstismar yokEPSS %1smackcoders · echo sign17 Eyl 2019
- CVE-2015-930624İzleyin
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv12 Ağu 2019
- CVE-2022-036019İzleyin
WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting
OrtaCVSS 4,8İstismar yokEPSS %1smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv28 Şub 2022
- CVE-2013-326317İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow
OrtaCVSS 4,3İstismar yokEPSS %2smackcoders · wp ultimate email marketer plugin5 Kas 2013
- CVE-2024-936417İzleyin
SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
OrtaCVSS 4,3İstismar yokEPSS %0smackcoders · sendgrid18 Eki 2024
- CVE-2025-569217İzleyin
Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions
OrtaCVSS 4,3İstismar yokEPSS %0smackcoders · lead form data collection to crm1 Tem 2025
- CVE-2022-324416İzleyin
Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation
OrtaCVSS 4,2İstismar yokEPSS %0smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 Eki 2022