ThemeGrill kayıtları
themegrill üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %30,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization2
- CWE-284 Improper Access Control2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-266 Incorrect Privilege Assignment1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-24882Kavram kanıtı | WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilitythemegrill · masteriyo · CWE-266 | Kritik9,8 | — | %2,1 | 17 May 2024 |
39İzleyin | CVE-2020-36837İstismar yok | ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Resetthemegrill · themegrill demo importer · CWE-862 | Kritik9,9 | — | %0,6 | 16 Eki 2024 |
37İzleyin | CVE-2020-36333Kavram kanıtı | themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.themegrill · themegrill demo importer · CWE-306 | Kritik9,1 | — | %4,1 | 5 May 2021 |
35İzleyin | CVE-2020-36334İstismar yok | themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.themegrill · themegrill demo importer · CWE-352 | Yüksek8,8 | — | %0,6 | 5 May 2021 |
27İzleyin | CVE-2023-3345Kavram kanıtı | LMS by Masteriyo < 1.6.8 - Information Exposurethemegrill · masteriyo · CWE-863 | Orta6,5 | — | %2,0 | 31 Tem 2023 |
26İzleyin | CVE-2024-0679Kavram kanıtı | ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installationthemegrill · colormag · CWE-862 | Orta6,5 | — | %1,3 | 20 Oca 2024 |
26İzleyin | CVE-2024-33540İstismar yok | WordPress ColorNews theme <= 1.2.6 - Cross Site Scripting (XSS) vulnerabilitythemegrill · colornews · CWE-79 | Orta6,5 | — | %0,3 | 29 Nis 2024 |
24İzleyin | CVE-2024-9218İstismar yok | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scriptingthemegrill · magazine blocks · CWE-79 | Orta6,1 | — | %0,4 | 2 Eki 2024 |
24İzleyin | CVE-2024-37432İstismar yok | WordPress Esteem theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerabilitythemegrill · esteem · CWE-79 | Orta6,1 | — | %0,3 | 22 Tem 2024 |
21İzleyin | CVE-2024-33939Kavram kanıtı | WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerabilitythemegrill · masteriyo · CWE-288 | Orta5,3 | — | %0,9 | 19 May 2025 |
21İzleyin | CVE-2024-1462İstismar yok | Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST APIthemegrill · maintenance page · CWE-284 | Orta5,3 | — | %0,5 | 13 Mar 2024 |
19İzleyin | CVE-2024-39629İstismar yok | WordPress Himalayas theme <= 1.3.2 - Cross Site Scripting (XSS) vulnerabilitythemegrill · himalayas · CWE-79 | Orta4,8 | — | %0,3 | 1 Ağu 2024 |
17İzleyin | CVE-2024-1370İstismar yok | Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposurethemegrill · maintenance page · CWE-284 | Orta4,3 | — | %0,4 | 13 Mar 2024 |
- CVE-2024-2488240Planlayın
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %2themegrill · masteriyo17 May 2024
- CVE-2020-3683739İzleyin
ThemeGrill Demo Importer 1.3.4 - 1.6.1 - Authorization Bypass to Site Reset
KritikCVSS 9,9İstismar yokEPSS %1themegrill · themegrill demo importer16 Eki 2024
- CVE-2020-3633337İzleyin
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.
KritikCVSS 9,1Kavram kanıtıEPSS %4themegrill · themegrill demo importer5 May 2021
- CVE-2020-3633435İzleyin
themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.
YüksekCVSS 8,8İstismar yokEPSS %1themegrill · themegrill demo importer5 May 2021
- CVE-2023-334527İzleyin
LMS by Masteriyo < 1.6.8 - Information Exposure
OrtaCVSS 6,5Kavram kanıtıEPSS %2themegrill · masteriyo31 Tem 2023
- CVE-2024-067926İzleyin
ColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installation
OrtaCVSS 6,5Kavram kanıtıEPSS %1themegrill · colormag20 Oca 2024
- CVE-2024-3354026İzleyin
WordPress ColorNews theme <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0themegrill · colornews29 Nis 2024
- CVE-2024-921824İzleyin
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0themegrill · magazine blocks2 Eki 2024
- CVE-2024-3743224İzleyin
WordPress Esteem theme <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0themegrill · esteem22 Tem 2024
- CVE-2024-3393921İzleyin
WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability
OrtaCVSS 5,3Kavram kanıtıEPSS %1themegrill · masteriyo19 May 2025
- CVE-2024-146221İzleyin
Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API
OrtaCVSS 5,3İstismar yokEPSS %1themegrill · maintenance page13 Mar 2024
- CVE-2024-3962919İzleyin
WordPress Himalayas theme <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 4,8İstismar yokEPSS %0themegrill · himalayas1 Ağu 2024
- CVE-2024-137017İzleyin
Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposure
OrtaCVSS 4,3İstismar yokEPSS %0themegrill · maintenance page13 Mar 2024