smartypantsplugins kayıtları
smartypantsplugins üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %6,7
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-178 Improper Handling of Case Sensitivity1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2021-24347Silahlaştırılmış | SP Project & Document Manager <2 4.22 - Authenticated Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-178 | Yüksek8,8 | — | %54,1 | 14 Haz 2021 |
36İzleyin | CVE-2021-4225İstismar yok | SP Project & Document Manager < 4.24 - Subscriber+ Shell Uploadsmartypantsplugins · sp project \& document manager · CWE-434 | Yüksek8,8 | — | %1,7 | 25 Nis 2022 |
35İzleyin | CVE-2023-3063İstismar yok | SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Changesmartypantsplugins · sp project \& document manager · CWE-639 | Yüksek8,8 | — | %0,7 | 29 Haz 2023 |
35İzleyin | CVE-2023-36677İstismar yok | WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injectionsmartypantsplugins · sp project \& document manager · CWE-89 | Yüksek8,8 | — | %0,7 | 3 Kas 2023 |
35İzleyin | CVE-2024-24868İstismar yok | WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injectionsmartypantsplugins · sp project \& document manager · CWE-89 | Yüksek8,8 | — | %0,5 | 28 Şub 2024 |
31İzleyin | CVE-2014-9178Kavram kanıtı | Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-documsmartypantsplugins · sp project \& document manager · CWE-89 | Yüksek7,5 | — | %4,6 | 2 Ara 2014 |
31İzleyin | CVE-2021-38324İstismar yok | SP Rental Manager <= 1.5.3 Unauthenticated SQL Injectionsmartypantsplugins · sp rental manager · CWE-89 | Yüksek7,5 | — | %1,8 | 9 Eyl 2021 |
26İzleyin | CVE-2022-1551İstismar yok | SP Project & Document Manager < 4.58 - Sensitive File Disclosuresmartypantsplugins · sp project \& document manager · CWE-425 | Orta6,5 | — | %1,0 | 25 Tem 2022 |
26İzleyin | CVE-2024-37224İstismar yok | WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerabilitysmartypantsplugins · sp project \& document manager · CWE-22 | Orta6,5 | — | %0,6 | 9 Tem 2024 |
26İzleyin | CVE-2024-3749İstismar yok | SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDORsmartypantsplugins · sp project \& document manager · CWE-639 | Orta6,5 | — | %0,5 | 15 May 2024 |
26İzleyin | CVE-2024-3748İstismar yok | SP Project & Document Manager <= 4.71 - Data Update via IDORsmartypantsplugins · sp project \& document manager · CWE-639 | Orta6,5 | — | %0,4 | 15 May 2024 |
24İzleyin | CVE-2021-38315İstismar yok | SP Project & Document Manager <= 4.25 Reflected Cross-Site Scriptingsmartypantsplugins · sp project \& document manager · CWE-79 | Orta6,1 | — | %0,9 | 16 Ağu 2021 |
24İzleyin | CVE-2022-34857İstismar yok | WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerabilitysmartypantsplugins · sp project \& document manager · CWE-79 | Orta6,1 | — | %0,6 | 22 Ağu 2022 |
19İzleyin | CVE-2023-36530İstismar yok | WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)smartypantsplugins · sp project \& document manager · CWE-79 | Orta4,8 | — | %0,4 | 10 Ağu 2023 |
18İzleyin | CVE-2013-3529Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote wordpress · wordpress · CWE-79 | Orta4,3 | — | %4,6 | 10 May 2013 |
- CVE-2021-2434751Planlayın
SP Project & Document Manager <2 4.22 - Authenticated Shell Upload
YüksekCVSS 8,8SilahlaştırılmışEPSS %54smartypantsplugins · sp project \& document manager14 Haz 2021
- CVE-2021-422536İzleyin
SP Project & Document Manager < 4.24 - Subscriber+ Shell Upload
YüksekCVSS 8,8İstismar yokEPSS %2smartypantsplugins · sp project \& document manager25 Nis 2022
- CVE-2023-306335İzleyin
SP Project & Document Manager <= 4.67 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change
YüksekCVSS 8,8İstismar yokEPSS %1smartypantsplugins · sp project \& document manager29 Haz 2023
- CVE-2023-3667735İzleyin
WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1smartypantsplugins · sp project \& document manager3 Kas 2023
- CVE-2024-2486835İzleyin
WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1smartypantsplugins · sp project \& document manager28 Şub 2024
- CVE-2014-917831İzleyin
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-docum
YüksekCVSS 7,5Kavram kanıtıEPSS %5smartypantsplugins · sp project \& document manager2 Ara 2014
- CVE-2021-3832431İzleyin
SP Rental Manager <= 1.5.3 Unauthenticated SQL Injection
YüksekCVSS 7,5İstismar yokEPSS %2smartypantsplugins · sp rental manager9 Eyl 2021
- CVE-2022-155126İzleyin
SP Project & Document Manager < 4.58 - Sensitive File Disclosure
OrtaCVSS 6,5İstismar yokEPSS %1smartypantsplugins · sp project \& document manager25 Tem 2022
- CVE-2024-3722426İzleyin
WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerability
OrtaCVSS 6,5İstismar yokEPSS %1smartypantsplugins · sp project \& document manager9 Tem 2024
- CVE-2024-374926İzleyin
SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR
OrtaCVSS 6,5İstismar yokEPSS %1smartypantsplugins · sp project \& document manager15 May 2024
- CVE-2024-374826İzleyin
SP Project & Document Manager <= 4.71 - Data Update via IDOR
OrtaCVSS 6,5İstismar yokEPSS %0smartypantsplugins · sp project \& document manager15 May 2024
- CVE-2021-3831524İzleyin
SP Project & Document Manager <= 4.25 Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1smartypantsplugins · sp project \& document manager16 Ağu 2021
- CVE-2022-3485724İzleyin
WordPress SP Project & Document Manager plugin <= 4.59 - Reflected Cross-Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %1smartypantsplugins · sp project \& document manager22 Ağu 2022
- CVE-2023-3653019İzleyin
WordPress SP Project & Document Manager Plugin <= 4.67 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 4,8İstismar yokEPSS %0smartypantsplugins · sp project \& document manager10 Ağu 2023
- CVE-2013-352918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote
OrtaCVSS 4,3Kavram kanıtıEPSS %5wordpress · wordpress10 May 2013