codesupply records
4 published records for vendor codesupply.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2021-24840No exploit | Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts Disclosurecodesupply · squaretype · CWE-639 | Medium5.3 | — | 1.2% | Nov 8, 2021 |
21Monitor | CVE-2024-9025No exploit | Sight – Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_titlecodesupply · sight · CWE-862 | Medium5.3 | — | 0.4% | Sep 26, 2024 |
21Monitor | CVE-2024-8965No exploit | Absolute Reviews <= 1.1.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Criteria Namecodesupply · absolute reviews · CWE-79 | Medium5.4 | — | 0.3% | Sep 27, 2024 |
17Monitor | CVE-2021-4426No exploit | Absolute Reviews <= 1.0.8 - Cross-Site Request Forgery Bypasscodesupply · absolute reviews · CWE-352 | Medium4.3 | — | 0.6% | Jul 12, 2023 |
- CVE-2021-2484021Monitor
Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts Disclosure
MediumCVSS 5.3No exploitEPSS 1%codesupply · squaretypeNov 8, 2021
- CVE-2024-902521Monitor
Sight – Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title
MediumCVSS 5.3No exploitEPSS 0%codesupply · sightSep 26, 2024
- CVE-2024-896521Monitor
Absolute Reviews <= 1.1.3 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Criteria Name
MediumCVSS 5.4No exploitEPSS 0%codesupply · absolute reviewsSep 27, 2024
- CVE-2021-442617Monitor
Absolute Reviews <= 1.0.8 - Cross-Site Request Forgery Bypass
MediumCVSS 4.3No exploitEPSS 1%codesupply · absolute reviewsJul 12, 2023