bravenewcode records
4 published records for vendor bravenewcode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-502 Deserialization of Untrusted Data1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-3417No exploit | WPtouch < 4.3.45 - Admin+ PHP Object Injectionbravenewcode · wptouch · CWE-502 | High8.8 | — | 0.9% | Jan 9, 2023 |
33Monitor | CVE-2022-3416No exploit | WPtouch < 4.3.45 - Admin+ Arbitrary File Uploadbravenewcode · wptouch · CWE-434 | High7.2 | — | 17.3% | Jan 9, 2023 |
31Monitor | CVE-2011-4803Proof of concept | SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commandwordpress · wordpress · CWE-89 | High7.5 | — | 2.6% | Dec 13, 2011 |
18Monitor | CVE-2010-4779No exploit | Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote wordpress · wordpress · CWE-79 | Medium4.3 | — | 1.9% | Apr 7, 2011 |
- CVE-2022-341735Monitor
WPtouch < 4.3.45 - Admin+ PHP Object Injection
HighCVSS 8.8No exploitEPSS 1%bravenewcode · wptouchJan 9, 2023
- CVE-2022-341633Monitor
WPtouch < 4.3.45 - Admin+ Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 17%bravenewcode · wptouchJan 9, 2023
- CVE-2011-480331Monitor
SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL command
HighCVSS 7.5Proof of conceptEPSS 3%wordpress · wordpressDec 13, 2011
- CVE-2010-477918Monitor
Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote
MediumCVSS 4.3No exploitEPSS 2%wordpress · wordpressApr 7, 2011