a3rev records
8 published records for vendor a3rev.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2022-0434Proof of concept | Page Views Count < 2.4.15 - Unauthenticated SQL Injectiona3rev · page view count · CWE-89 | Critical9.8 | — | 14.8% | Mar 7, 2022 |
32Monitor | CVE-2025-2816No exploit | Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Updatea3rev · page view count · CWE-862 | High8.1 | — | 0.4% | Apr 30, 2025 |
26Monitor | CVE-2023-23973No exploit | WordPress Contact Us page - Contact people LITE Plugin <= 3.7.0 is vulnerable to Cross Site Request Forgery (CSRF)a3rev · contact us page - contact people · CWE-352 | Medium6.5 | — | 0.2% | Mar 1, 2023 |
21Monitor | CVE-2021-24509No exploit | Page View Counts < 2.4.9 - Contributor+ Stored XSSa3rev · page view count · CWE-79 | Medium5.4 | — | 0.6% | Aug 9, 2021 |
21Monitor | CVE-2023-0095No exploit | Page View Count < 2.6.1 - Contributor+ Stored XSSa3rev · page view count · CWE-79 | Medium5.4 | — | 0.6% | Feb 6, 2023 |
21Monitor | CVE-2025-5123No exploit | Contact Us Page – Contact People <= 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via style Parametera3rev · contact us page - contact people · CWE-79 | Medium5.4 | — | 0.2% | Jun 12, 2025 |
19Monitor | CVE-2023-29097No exploit | WordPress a3 Portfolio Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS)a3rev · a3 portfolio · CWE-79 | Medium4.8 | — | 0.4% | Aug 14, 2023 |
17Monitor | CVE-2022-40131No exploit | WordPress Page View Count plugin <= 2.5.5 - Cross-Site Request Forgery (CSRF) vulnerabilitya3rev · page view count · CWE-352 | Medium4.3 | — | 0.3% | Nov 3, 2022 |
- CVE-2022-043443Plan
Page Views Count < 2.4.15 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 15%a3rev · page view countMar 7, 2022
- CVE-2025-281632Monitor
Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
HighCVSS 8.1No exploitEPSS 0%a3rev · page view countApr 30, 2025
- CVE-2023-2397326Monitor
WordPress Contact Us page - Contact people LITE Plugin <= 3.7.0 is vulnerable to Cross Site Request Forgery (CSRF)
MediumCVSS 6.5No exploitEPSS 0%a3rev · contact us page - contact peopleMar 1, 2023
- CVE-2021-2450921Monitor
Page View Counts < 2.4.9 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%a3rev · page view countAug 9, 2021
- CVE-2023-009521Monitor
Page View Count < 2.6.1 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 1%a3rev · page view countFeb 6, 2023
- CVE-2025-512321Monitor
Contact Us Page – Contact People <= 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via style Parameter
MediumCVSS 5.4No exploitEPSS 0%a3rev · contact us page - contact peopleJun 12, 2025
- CVE-2023-2909719Monitor
WordPress a3 Portfolio Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%a3rev · a3 portfolioAug 14, 2023
- CVE-2022-4013117Monitor
WordPress Page View Count plugin <= 2.5.5 - Cross-Site Request Forgery (CSRF) vulnerability
MediumCVSS 4.3No exploitEPSS 0%a3rev · page view countNov 3, 2022