wpvibes kayıtları
wpvibes üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-862 Missing Authorization1
- CWE-863 Incorrect Authorization1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2023-5674İstismar yok | WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs/send_mail endpointwpvibes · wp mail log · CWE-89 | Yüksek8,8 | — | %10,8 | 26 Ara 2023 |
35İzleyin | CVE-2023-5673İstismar yok | WP Mail Log < 1.1.3 – Contributor+ Arbitrary File Upload to RCEwpvibes · wp mail log · CWE-434 | Yüksek8,8 | — | %1,1 | 26 Ara 2023 |
35İzleyin | CVE-2023-5645İstismar yok | WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpointwpvibes · wp mail log · CWE-89 | Yüksek8,8 | — | %0,7 | 26 Ara 2023 |
35İzleyin | CVE-2023-51410İstismar yok | WordPress WP Mail Log Plugin <= 1.1.2 is vulnerable to Arbitrary File Uploadwpvibes · wp mail log · CWE-434 | Yüksek8,8 | — | %0,6 | 29 Ara 2023 |
35İzleyin | CVE-2022-45807İstismar yok | WordPress WP Mail Log Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF)wpvibes · wp mail log · CWE-352 | Yüksek8,8 | — | %0,3 | 2 Şub 2023 |
30İzleyin | CVE-2023-5644İstismar yok | WP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpointswpvibes · wp mail log · CWE-863 | Yüksek7,6 | — | %0,5 | 26 Ara 2023 |
28İzleyin | CVE-2022-3764İstismar yok | Form Vibes < 1.4.5 - Admin+ SQLiwpvibes · form vibes · CWE-89 | Yüksek7,2 | — | %1,0 | 16 Oca 2024 |
28İzleyin | CVE-2023-47530İstismar yok | WordPress Redirect 404 Error Page to Homepage or Custom Page with Logs Plugin <= 1.8.7 is vulnerable to SQL Injectionwpvibes · redirect 404 error page to homepage or custom page with logs · CWE-89 | Yüksek7,2 | — | %0,7 | 18 Ara 2023 |
26İzleyin | CVE-2023-5672İstismar yok | WP Mail Log < 1.1.3 – Contributor+ LFI in wml_logs/send_mail endpointwpvibes · wp mail log · CWE-22 | Orta6,5 | — | %0,7 | 26 Ara 2023 |
26İzleyin | CVE-2021-24767İstismar yok | Redirect 404 Error Page to Homepage or Custom Page with Logs < 1.7.9 - Log Deletion via CSRFwpvibes · redirect 404 error page to homepage or custom page with logs · CWE-352 | Orta6,5 | — | %0,5 | 8 Kas 2021 |
26İzleyin | CVE-2024-5325İstismar yok | Form Vibes <= 1.4.10 - Authenticated (Subscriber+) SQL Injection via fv_export_datawpvibes · form vibes · CWE-89 | Orta6,5 | — | %0,5 | 12 Tem 2024 |
24İzleyin | CVE-2023-3088İstismar yok | WP Mail Log <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting via Emailwpvibes · wp mail log · CWE-79 | Orta6,1 | — | %0,5 | 12 Tem 2023 |
21İzleyin | CVE-2023-0443İstismar yok | AnyWhere Elementor < 1.2.8 - Freemius API Key Disclosurewpvibes · anywhere elementor · CWE-200 | Orta5,3 | — | %0,6 | 30 May 2023 |
21İzleyin | CVE-2024-5309İstismar yok | Form Vibes – Database Manager for Forms <= 1.4.12 - Missing Authorization in Multiple Functionswpvibes · form vibes · CWE-862 | Orta5,4 | — | %0,3 | 5 Eyl 2024 |
- CVE-2023-567438İzleyin
WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs/send_mail endpoint
YüksekCVSS 8,8İstismar yokEPSS %11wpvibes · wp mail log26 Ara 2023
- CVE-2023-567335İzleyin
WP Mail Log < 1.1.3 – Contributor+ Arbitrary File Upload to RCE
YüksekCVSS 8,8İstismar yokEPSS %1wpvibes · wp mail log26 Ara 2023
- CVE-2023-564535İzleyin
WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpoint
YüksekCVSS 8,8İstismar yokEPSS %1wpvibes · wp mail log26 Ara 2023
- CVE-2023-5141035İzleyin
WordPress WP Mail Log Plugin <= 1.1.2 is vulnerable to Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1wpvibes · wp mail log29 Ara 2023
- CVE-2022-4580735İzleyin
WordPress WP Mail Log Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0wpvibes · wp mail log2 Şub 2023
- CVE-2023-564430İzleyin
WP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpoints
YüksekCVSS 7,6İstismar yokEPSS %0wpvibes · wp mail log26 Ara 2023
- CVE-2022-376428İzleyin
Form Vibes < 1.4.5 - Admin+ SQLi
YüksekCVSS 7,2İstismar yokEPSS %1wpvibes · form vibes16 Oca 2024
- CVE-2023-4753028İzleyin
WordPress Redirect 404 Error Page to Homepage or Custom Page with Logs Plugin <= 1.8.7 is vulnerable to SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1wpvibes · redirect 404 error page to homepage or custom page with logs18 Ara 2023
- CVE-2023-567226İzleyin
WP Mail Log < 1.1.3 – Contributor+ LFI in wml_logs/send_mail endpoint
OrtaCVSS 6,5İstismar yokEPSS %1wpvibes · wp mail log26 Ara 2023
- CVE-2021-2476726İzleyin
Redirect 404 Error Page to Homepage or Custom Page with Logs < 1.7.9 - Log Deletion via CSRF
OrtaCVSS 6,5İstismar yokEPSS %1wpvibes · redirect 404 error page to homepage or custom page with logs8 Kas 2021
- CVE-2024-532526İzleyin
Form Vibes <= 1.4.10 - Authenticated (Subscriber+) SQL Injection via fv_export_data
OrtaCVSS 6,5İstismar yokEPSS %0wpvibes · form vibes12 Tem 2024
- CVE-2023-308824İzleyin
WP Mail Log <= 1.1.1 - Unauthenticated Stored Cross-Site Scripting via Email
OrtaCVSS 6,1İstismar yokEPSS %0wpvibes · wp mail log12 Tem 2023
- CVE-2023-044321İzleyin
AnyWhere Elementor < 1.2.8 - Freemius API Key Disclosure
OrtaCVSS 5,3İstismar yokEPSS %1wpvibes · anywhere elementor30 May 2023
- CVE-2024-530921İzleyin
Form Vibes – Database Manager for Forms <= 1.4.12 - Missing Authorization in Multiple Functions
OrtaCVSS 5,4İstismar yokEPSS %0wpvibes · form vibes5 Eyl 2024