Arvandy (Patchstack Alliance)
6 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2023-48287No exploit | WordPress TextMe SMS plugin <= 1.9.0 - Broken Access Control vulnerabilitymatat technologies · textme sms · CWE-862 | Medium5.4 | — | 0.5% | Dec 9, 2024 |
17Monitor | CVE-2023-47871No exploit | WordPress Contact Form to Any API plugin <= 1.1.6 - Broken Access Control vulnerabilityit path solutions · contact form to any api · CWE-862 | Medium4.3 | — | 0.5% | Dec 9, 2024 |
19Monitor | CVE-2024-21747No exploit | WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injectionwedevs · wp erp · CWE-89 | Medium4.9 | — | 0.6% | Jan 8, 2024 |
36Monitor | CVE-2023-49161No exploit | WordPress Bravo Translate Plugin <= 1.2 is vulnerable to SQL Injectionguelbetech · bravo translate · CWE-89 | Critical9.1 | — | 0.6% | Dec 20, 2023 |
28Monitor | CVE-2023-32741No exploit | WordPress Contact Form to Any API Plugin <= 1.1.2 is vulnerable to SQL Injectionitpathsolutions · contact form to any api · CWE-89 | High7.2 | — | 0.7% | Nov 3, 2023 |
24Monitor | CVE-2023-37988Proof of concept | WordPress Contact Form Generator Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)creative-solutions · contact form generator · CWE-79 | Medium6.1 | — | 1.3% | Aug 10, 2023 |
- CVE-2023-4828721Monitor
WordPress TextMe SMS plugin <= 1.9.0 - Broken Access Control vulnerability
MediumCVSS 5.4No exploitEPSS 0%matat technologies · textme smsDec 9, 2024
- CVE-2023-4787117Monitor
WordPress Contact Form to Any API plugin <= 1.1.6 - Broken Access Control vulnerability
MediumCVSS 4.3No exploitEPSS 0%it path solutions · contact form to any apiDec 9, 2024
- CVE-2024-2174719Monitor
WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection
MediumCVSS 4.9No exploitEPSS 1%wedevs · wp erpJan 8, 2024
- CVE-2023-4916136Monitor
WordPress Bravo Translate Plugin <= 1.2 is vulnerable to SQL Injection
CriticalCVSS 9.1No exploitEPSS 1%guelbetech · bravo translateDec 20, 2023
- CVE-2023-3274128Monitor
WordPress Contact Form to Any API Plugin <= 1.1.2 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%itpathsolutions · contact form to any apiNov 3, 2023
- CVE-2023-3798824Monitor
WordPress Contact Form Generator Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1Proof of conceptEPSS 1%creative-solutions · contact form generatorAug 10, 2023