AmentoTech records
8 published records for vendor amentotech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 12.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-283 Unverified Ownership2
- CWE-288 Authentication Bypass Using an Alternate Path or Channel2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-639 Authorization Bypass Through User-Controlled Key2
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2021-24499Proof of concept | Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Executionamentotech · workreap · CWE-434 | Critical9.8 | — | 60.1% | Aug 9, 2021 |
39Monitor | CVE-2025-4973No exploit | Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'amentotech · workreap · CWE-288 | Critical9.8 | — | 0.5% | Jun 12, 2025 |
39Monitor | CVE-2024-13446No exploit | Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeoveramentotech · workreap · CWE-288 | Critical9.8 | — | 0.4% | Mar 12, 2025 |
35Monitor | CVE-2025-5012No exploit | Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media'amentotech · workreap · CWE-434 | High8.8 | — | 0.6% | Jun 12, 2025 |
32Monitor | CVE-2021-24501No exploit | Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actionsamentotech · workreap · CWE-283 | High8.1 | — | 1.3% | Aug 9, 2021 |
32Monitor | CVE-2021-24500No exploit | Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilitiesamentotech · workreap · CWE-283 | High8.1 | — | 0.6% | Aug 9, 2021 |
30Monitor | CVE-2022-3846No exploit | Workreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDORamentotech · workreap · CWE-639 | High7.5 | — | 0.8% | Dec 5, 2022 |
26Monitor | CVE-2022-4239No exploit | Workreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDORamentotech · workreap · CWE-639 | Medium6.5 | — | 0.6% | Dec 26, 2022 |
- CVE-2021-2449957Plan
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CriticalCVSS 9.8Proof of conceptEPSS 60%amentotech · workreapAug 9, 2021
- CVE-2025-497339Monitor
Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'
CriticalCVSS 9.8No exploitEPSS 0%amentotech · workreapJun 12, 2025
- CVE-2024-1344639Monitor
Workreap <= 3.2.5 - Unauthenticated Privilege Escalation via Account Takeover
CriticalCVSS 9.8No exploitEPSS 0%amentotech · workreapMar 12, 2025
- CVE-2025-501235Monitor
Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_media'
HighCVSS 8.8No exploitEPSS 1%amentotech · workreapJun 12, 2025
- CVE-2021-2450132Monitor
Workreap theme < 2.2.2 - Missing Authorization Checks in Ajax Actions
HighCVSS 8.1No exploitEPSS 1%amentotech · workreapAug 9, 2021
- CVE-2021-2450032Monitor
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
HighCVSS 8.1No exploitEPSS 1%amentotech · workreapAug 9, 2021
- CVE-2022-384630Monitor
Workreap - Freelance Marketplace and Directory < 2.6.3 - Subscriber+ Private Message Disclosure via IDOR
HighCVSS 7.5No exploitEPSS 1%amentotech · workreapDec 5, 2022
- CVE-2022-423926Monitor
Workreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDOR
MediumCVSS 6.5No exploitEPSS 1%amentotech · workreapDec 26, 2022