artbees records
20 published records for vendor artbees.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 35%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-284 Improper Access Control3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-38388No exploit | WordPress Jupiter X Core plugin <= 3.3.5 - Unauth. Arbitrary File Upload vulnerabilityartbees · jupiter x core · CWE-434 | Critical9.8 | — | 1.7% | Mar 26, 2024 |
39Monitor | CVE-2024-7772No exploit | Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Uploadartbees · jupiter x core · CWE-434 | Critical9.8 | — | 1.5% | Sep 26, 2024 |
39Monitor | CVE-2023-38389No exploit | WordPress Jupiter X Core plugin <= 3.3.8 - Unauthenticated Account Takeover vulnerabilityartbees · jupiter x core · CWE-863 | Critical9.8 | — | 1.4% | Jun 21, 2024 |
39Monitor | CVE-2024-7781No exploit | Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeoverartbees · jupiter x core · CWE-288 | Critical9.8 | — | 1.0% | Sep 26, 2024 |
35Monitor | CVE-2025-0366No exploit | Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)artbees · jupiter x core · CWE-98 | High8.8 | — | 1.6% | Feb 1, 2025 |
35Monitor | CVE-2022-1657No exploit | JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Local File Inclusionartbees · jupiter · CWE-22 | High8.8 | — | 1.6% | Jun 13, 2022 |
35Monitor | CVE-2022-1654No exploit | Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalationartbees · jupiter · CWE-269 | High8.8 | — | 1.6% | Jun 13, 2022 |
35Monitor | CVE-2023-32110No exploit | WordPress JupiterX theme <= 3.0.0 - Auth. Local File Inclusion vulnerabilityartbees · jupiterx · CWE-22 | High8.8 | — | 0.8% | May 17, 2024 |
35Monitor | CVE-2023-38385No exploit | WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerabilityartbees · jupiter x core · CWE-862 | High8.8 | — | 0.6% | Dec 13, 2024 |
35Monitor | CVE-2023-38394No exploit | WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerabilityartbees · jupiter x core · CWE-862 | High8.8 | — | 0.4% | Jun 19, 2024 |
32Monitor | CVE-2025-2105No exploit | Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHARartbees · jupiter x core · CWE-502 | High8.1 | — | 0.8% | Apr 26, 2025 |
30Monitor | CVE-2023-3813No exploit | Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Downloadartbees · jupiter x core · CWE-22 | High7.5 | — | 1.2% | Jul 20, 2023 |
29Monitor | CVE-2022-1659No exploit | JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Serviceartbees · jupiterx · CWE-284 | High7.3 | — | 0.9% | Jun 13, 2022 |
26Monitor | CVE-2025-0365No exploit | Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Readartbees · jupiter x core · CWE-22 | Medium6.5 | — | 0.7% | Feb 1, 2025 |
21Monitor | CVE-2022-1658No exploit | Jupiter Theme <= 6.10.1 - Authenticated Arbitrary Plugin Deletionartbees · jupiter · CWE-284 | Medium5.4 | — | 0.7% | Jun 13, 2022 |
21Monitor | CVE-2022-1656No exploit | JupiterX Theme <= 2.0.6 and JupiterX Core <= 2.0.6 - Authenticated Arbitrary Plugin Deactivation and Settings Modificationartbees · jupiter x core · CWE-284 | Medium5.4 | — | 0.5% | Jun 13, 2022 |
21Monitor | CVE-2024-12316No exploit | Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Exportartbees · jupiter x core · CWE-862 | Medium5.3 | — | 0.4% | Jan 7, 2025 |
21Monitor | CVE-2025-3888No exploit | Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVGartbees · jupiter x core · CWE-79 | Medium5.4 | — | 0.3% | May 17, 2025 |
21Monitor | CVE-2024-4608No exploit | SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via id artbees · sellkit · CWE-79 | Medium5.4 | — | 0.3% | Jun 6, 2024 |
17Monitor | CVE-2024-12033No exploit | Jupiter X Core <= 4.8.5 - Missing Authorization to Authenticated Library Syncartbees · jupiter x core · CWE-862 | Medium4.3 | — | 0.3% | Jan 7, 2025 |
- CVE-2023-3838840Plan
WordPress Jupiter X Core plugin <= 3.3.5 - Unauth. Arbitrary File Upload vulnerability
CriticalCVSS 9.8No exploitEPSS 2%artbees · jupiter x coreMar 26, 2024
- CVE-2024-777239Monitor
Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 2%artbees · jupiter x coreSep 26, 2024
- CVE-2023-3838939Monitor
WordPress Jupiter X Core plugin <= 3.3.8 - Unauthenticated Account Takeover vulnerability
CriticalCVSS 9.8No exploitEPSS 1%artbees · jupiter x coreJun 21, 2024
- CVE-2024-778139Monitor
Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover
CriticalCVSS 9.8No exploitEPSS 1%artbees · jupiter x coreSep 26, 2024
- CVE-2025-036635Monitor
Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution)
HighCVSS 8.8No exploitEPSS 2%artbees · jupiter x coreFeb 1, 2025
- CVE-2022-165735Monitor
JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Local File Inclusion
HighCVSS 8.8No exploitEPSS 2%artbees · jupiterJun 13, 2022
- CVE-2022-165435Monitor
Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation
HighCVSS 8.8No exploitEPSS 2%artbees · jupiterJun 13, 2022
- CVE-2023-3211035Monitor
WordPress JupiterX theme <= 3.0.0 - Auth. Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%artbees · jupiterxMay 17, 2024
- CVE-2023-3838535Monitor
WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%artbees · jupiter x coreDec 13, 2024
- CVE-2023-3839435Monitor
WordPress Jupiter X Core plugin <= 3.3.0 - Multiple Auth. Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%artbees · jupiter x coreJun 19, 2024
- CVE-2025-210532Monitor
Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR
HighCVSS 8.1No exploitEPSS 1%artbees · jupiter x coreApr 26, 2025
- CVE-2023-381330Monitor
Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download
HighCVSS 7.5No exploitEPSS 1%artbees · jupiter x coreJul 20, 2023
- CVE-2022-165929Monitor
JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service
HighCVSS 7.3No exploitEPSS 1%artbees · jupiterxJun 13, 2022
- CVE-2025-036526Monitor
Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read
MediumCVSS 6.5No exploitEPSS 1%artbees · jupiter x coreFeb 1, 2025
- CVE-2022-165821Monitor
Jupiter Theme <= 6.10.1 - Authenticated Arbitrary Plugin Deletion
MediumCVSS 5.4No exploitEPSS 1%artbees · jupiterJun 13, 2022
- CVE-2022-165621Monitor
JupiterX Theme <= 2.0.6 and JupiterX Core <= 2.0.6 - Authenticated Arbitrary Plugin Deactivation and Settings Modification
MediumCVSS 5.4No exploitEPSS 1%artbees · jupiter x coreJun 13, 2022
- CVE-2024-1231621Monitor
Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export
MediumCVSS 5.3No exploitEPSS 0%artbees · jupiter x coreJan 7, 2025
- CVE-2025-388821Monitor
Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG
MediumCVSS 5.4No exploitEPSS 0%artbees · jupiter x coreMay 17, 2025
- CVE-2024-460821Monitor
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via id
MediumCVSS 5.4No exploitEPSS 0%artbees · sellkitJun 6, 2024
- CVE-2024-1203317Monitor
Jupiter X Core <= 4.8.5 - Missing Authorization to Authenticated Library Sync
MediumCVSS 4.3No exploitEPSS 0%artbees · jupiter x coreJan 7, 2025