coffee2code records
11 published records for vendor coffee2code.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-45360No exploit | WordPress Commenter Emails Plugin <= 2.6.1 is vulnerable to CSV Injectioncoffee2code · commenter emails · CWE-1236 | Critical9.8 | — | 0.6% | Nov 7, 2023 |
21Monitor | CVE-2024-7416No exploit | Reveal Template <= 3.7 - Unauthenticated Full Path Disclosurecoffee2code · reveal template · CWE-200 | Medium5.3 | — | 0.5% | Aug 12, 2024 |
21Monitor | CVE-2024-7413No exploit | Obfuscate Email <= 3.8.1 - Unauthenticated Full Path Disclosurecoffee2code · obfuscate email · CWE-200 | Medium5.3 | — | 0.5% | Aug 12, 2024 |
21Monitor | CVE-2024-7382No exploit | Linkify Text <= 1.9.1 - Unauthenticated Full Path Disclosurecoffee2code · linkify text · CWE-200 | Medium5.3 | — | 0.5% | Aug 12, 2024 |
21Monitor | CVE-2024-7412No exploit | No Update Nag <= 1.4.12 - Unauthenticated Full Path Disclosurecoffee2code · no update nag · CWE-200 | Medium5.3 | — | 0.5% | Aug 12, 2024 |
21Monitor | CVE-2024-6546No exploit | One Click Close Comments <= 2.7.1 - Unauthenticated Full Path Disclosurecoffee2code · one click close comments · CWE-200 | Medium5.3 | — | 0.4% | Jul 26, 2024 |
21Monitor | CVE-2024-7415No exploit | Remember Me Controls <= 2.0.1 - Unauthenticated Full Path Disclosurecoffee2code · remember me controls · CWE-200 | Medium5.3 | — | 0.4% | Sep 6, 2024 |
21Monitor | CVE-2024-6549No exploit | Admin Post Navigation <= 2.1 - Unauthenticated Full Path Disclosurecoffee2code · admin post navigation · CWE-200 | Medium5.3 | — | 0.4% | Jul 26, 2024 |
21Monitor | CVE-2024-6544No exploit | Custom Post Limits <= 4.4.1 - Unauthenticated Full Path Disclosurecoffee2code · custom post limits · CWE-200 | Medium5.3 | — | 0.4% | Sep 13, 2024 |
21Monitor | CVE-2024-6548No exploit | Add Admin JavaScript <= 2.0 - Unauthenticated Full Path Dislcosurecoffee2code · add admin javascript · CWE-200 | Medium5.3 | — | 0.4% | Jul 26, 2024 |
21Monitor | CVE-2024-6545No exploit | Admin Trim Interface <= 3.5.1 - Unauthenticated Full Path Disclosurecoffee2code · admin trim interface · CWE-200 | Medium5.3 | — | 0.4% | Jul 26, 2024 |
- CVE-2022-4536039Monitor
WordPress Commenter Emails Plugin <= 2.6.1 is vulnerable to CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%coffee2code · commenter emailsNov 7, 2023
- CVE-2024-741621Monitor
Reveal Template <= 3.7 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 1%coffee2code · reveal templateAug 12, 2024
- CVE-2024-741321Monitor
Obfuscate Email <= 3.8.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · obfuscate emailAug 12, 2024
- CVE-2024-738221Monitor
Linkify Text <= 1.9.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · linkify textAug 12, 2024
- CVE-2024-741221Monitor
No Update Nag <= 1.4.12 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · no update nagAug 12, 2024
- CVE-2024-654621Monitor
One Click Close Comments <= 2.7.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · one click close commentsJul 26, 2024
- CVE-2024-741521Monitor
Remember Me Controls <= 2.0.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · remember me controlsSep 6, 2024
- CVE-2024-654921Monitor
Admin Post Navigation <= 2.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · admin post navigationJul 26, 2024
- CVE-2024-654421Monitor
Custom Post Limits <= 4.4.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · custom post limitsSep 13, 2024
- CVE-2024-654821Monitor
Add Admin JavaScript <= 2.0 - Unauthenticated Full Path Dislcosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · add admin javascriptJul 26, 2024
- CVE-2024-654521Monitor
Admin Trim Interface <= 3.5.1 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3No exploitEPSS 0%coffee2code · admin trim interfaceJul 26, 2024