İçeriğe atla
Noroxi

UpdraftPlus kayıtları

updraftplus üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%10,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2017-16871
    32İzleyin

    The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/pl

    YüksekCVSS 8,1İstismar yokEPSS %2

    updraftplus · updraftplus17 Kas 2017

  • CVE-2017-16870
    32İzleyin

    The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.

    YüksekCVSS 8,1İstismar yokEPSS %1

    updraftplus · updraftplus17 Kas 2017

  • CVE-2023-0157
    29İzleyin

    All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS

    OrtaCVSS 4,8Kavram kanıtıEPSS %32

    updraftplus · all-in-one security10 Nis 2023

  • CVE-2022-0633
    27İzleyin

    UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download

    OrtaCVSS 6,5İstismar yokEPSS %2

    updraftplus · updraftplus17 Şub 2022

  • CVE-2022-0864
    26İzleyin

    UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1Kavram kanıtıEPSS %7

    updraftplus · updraftplus4 Nis 2022

  • CVE-2023-0156
    25İzleyin

    All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal

    OrtaCVSS 4,9Kavram kanıtıEPSS %20

    updraftplus · all-in-one security10 Nis 2023

  • CVE-2023-1119
    24İzleyin

    Multiple Plugins - Cross-Site Scripting From Third-party Library

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    srbtranslatin project · srbtranslatin10 Tem 2023

  • CVE-2021-25022
    24İzleyin

    UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    updraftplus · updraftplus3 Oca 2022

  • CVE-2015-9360
    24İzleyin

    The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().

    OrtaCVSS 6,1İstismar yokEPSS %1

    updraftplus · updraftplus28 Ağu 2019

  • CVE-2017-18593
    24İzleyin

    The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.

    OrtaCVSS 6,1İstismar yokEPSS %1

    updraftplus · updraftplus28 Ağu 2019

  • CVE-2021-25089
    24İzleyin

    UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    updraftplus · updraftplus1 Şub 2022

  • CVE-2024-1037
    24İzleyin

    All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    updraftplus · all-in-one security7 Şub 2024

  • CVE-2023-26530
    24İzleyin

    WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)

    OrtaCVSS 6,1İstismar yokEPSS %0

    updraftplus · updraft17 Ağu 2023

  • CVE-2023-32960
    24İzleyin

    WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)

    OrtaCVSS 6,1İstismar yokEPSS %0

    updraftplus · updraftplus22 Haz 2023

  • CVE-2022-4346
    21İzleyin

    All In One WP Security & Firewall < 5.1.3 - Configuration Leak

    OrtaCVSS 5,3İstismar yokEPSS %1

    updraftplus · all-in-one security23 Oca 2023

  • CVE-2022-4097
    21İzleyin

    All In One WP Security & Firewall < 5.0.8 - IP Spoofing

    OrtaCVSS 5,3İstismar yokEPSS %1

    updraftplus · all-in-one security12 Ara 2022

  • CVE-2023-5982
    21İzleyin

    UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update

    OrtaCVSS 5,4İstismar yokEPSS %0

    updraftplus · updraftplus7 Kas 2023

  • CVE-2021-24423
    19İzleyin

    UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting

    OrtaCVSS 4,8İstismar yokEPSS %1

    updraftplus · updraftplus24 Oca 2022

  • CVE-2025-3951
    16İzleyin

    WP-Optimize < 4.2.0 - Admin+ SQLi

    OrtaCVSS 4,1İstismar yokEPSS %0

    updraftplus · wp-optimize2 Haz 2025