Astoundify records
7 published records for vendor astoundify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-862 Missing Authorization2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-269 Improper Privilege Management1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-32511No exploit | WordPress Simple Registration for WooCommerce plugin <= 1.5.6 - Unauthenticated Privilege Escalation vulnerabilityastoundify · simple registration for woocommerce · CWE-269 | Critical9.8 | — | 0.5% | May 17, 2024 |
39Monitor | CVE-2024-52480No exploit | WordPress Jobify plugin < 4.3.0 - Broken Access Control vulnerabilityastoundify · jobify · CWE-862 | Critical9.8 | — | 0.4% | Dec 9, 2024 |
35Monitor | CVE-2024-52479No exploit | WordPress Jobify plugin < 4.3.0 - Cross Site Request Forgery (CSRF) vulnerabilityastoundify · jobify · CWE-352 | High8.8 | — | 0.2% | Dec 2, 2024 |
30Monitor | CVE-2024-52481No exploit | WordPress Jobify theme < 4.3.0 - Unauthenticated Arbitrary File Read vulnerabilityastoundify · jobify · CWE-22 | High7.5 | — | 0.7% | Nov 28, 2024 |
26Monitor | CVE-2024-13698No exploit | Jobify - Job Board WordPress Theme <= 4.2.7 - Missing Authorization to Unauthenticated Server-Side Request Forgery, Arbitrary Image Upload, and Image Generationastoundify · jobify · CWE-862 | Medium6.5 | — | 0.3% | Jan 24, 2025 |
24Monitor | CVE-2023-6978No exploit | WP Job Manager – Company Profiles <= 1.7 - Reflected Cross-Site Scriptingastoundify · wp job manager · CWE-79 | Medium6.1 | — | 0.3% | Dec 4, 2024 |
21Monitor | CVE-2024-52478No exploit | WordPress Jobify theme < 4.3.0 - Cross Site Scripting (XSS) vulnerabilityastoundify · jobify · CWE-79 | Medium5.4 | — | 0.3% | Dec 2, 2024 |
- CVE-2024-3251139Monitor
WordPress Simple Registration for WooCommerce plugin <= 1.5.6 - Unauthenticated Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%astoundify · simple registration for woocommerceMay 17, 2024
- CVE-2024-5248039Monitor
WordPress Jobify plugin < 4.3.0 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%astoundify · jobifyDec 9, 2024
- CVE-2024-5247935Monitor
WordPress Jobify plugin < 4.3.0 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%astoundify · jobifyDec 2, 2024
- CVE-2024-5248130Monitor
WordPress Jobify theme < 4.3.0 - Unauthenticated Arbitrary File Read vulnerability
HighCVSS 7.5No exploitEPSS 1%astoundify · jobifyNov 28, 2024
- CVE-2024-1369826Monitor
Jobify - Job Board WordPress Theme <= 4.2.7 - Missing Authorization to Unauthenticated Server-Side Request Forgery, Arbitrary Image Upload, and Image Generation
MediumCVSS 6.5No exploitEPSS 0%astoundify · jobifyJan 24, 2025
- CVE-2023-697824Monitor
WP Job Manager – Company Profiles <= 1.7 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%astoundify · wp job managerDec 4, 2024
- CVE-2024-5247821Monitor
WordPress Jobify theme < 4.3.0 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%astoundify · jobifyDec 2, 2024