Dev4Press records
12 published records for vendor dev4press.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-0852No exploit | coreActivity < 1.8.1 - Unauthenticated Stored XSSdev4press · coreactivity · CWE-79 | High8.8 | — | 0.7% | May 15, 2025 |
30Monitor | CVE-2014-2839No exploit | SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands dev4press · gd star rating · CWE-89 | High7.5 | — | 1.6% | Jan 12, 2015 |
28Monitor | CVE-2023-46821No exploit | WordPress GD Security Headers Plugin <= 1.7 is vulnerable to SQL Injectiondev4press · gd security headers · CWE-89 | High7.2 | — | 0.6% | Nov 6, 2023 |
27Monitor | CVE-2014-2838No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijackdev4press · gd star rating · CWE-352 | Medium6.8 | — | 1.0% | Jan 12, 2015 |
24Monitor | CVE-2017-18591No exploit | The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.dev4press · gd rating system · CWE-79 | Medium6.1 | — | 0.9% | Aug 27, 2019 |
24Monitor | CVE-2023-3122No exploit | GD Mail Queue <= 3.9.3 - Unauthenticated Stored Cross-Site Scripting via Emaildev4press · gd mail queue · CWE-79 | Medium6.1 | — | 0.5% | Jul 12, 2023 |
24Monitor | CVE-2024-25093No exploit | WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS)dev4press · gd rating system · CWE-79 | Medium6.1 | — | 0.4% | Feb 29, 2024 |
24Monitor | CVE-2023-40330No exploit | WordPress GD Security Headers Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)dev4press · gd security headers · CWE-79 | Medium6.1 | — | 0.4% | Sep 27, 2023 |
21Monitor | CVE-2024-0868No exploit | coreActivity < 2.1 - Unauthenticated IP Spoofingdev4press · coreactivity · CWE-290 | Medium5.3 | — | 0.5% | Apr 17, 2024 |
21Monitor | CVE-2022-45816No exploit | WordPress GD bbPress Attachments Plugin <= 4.3.1 is vulnerable to Cross Site Scripting (XSS)dev4press · gd bbpress attachments · CWE-79 | Medium5.4 | — | 0.4% | Dec 6, 2022 |
18Monitor | CVE-2015-5481No exploit | Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attdev4press · gd bbpress attachments · CWE-79 | Medium4.3 | — | 2.1% | Aug 18, 2015 |
17Monitor | CVE-2015-5482No exploit | Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and dev4press · gd bbpress attachments · CWE-22 | Medium4.0 | — | 1.8% | Aug 18, 2015 |
- CVE-2024-085235Monitor
coreActivity < 1.8.1 - Unauthenticated Stored XSS
HighCVSS 8.8No exploitEPSS 1%dev4press · coreactivityMay 15, 2025
- CVE-2014-283930Monitor
SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands
HighCVSS 7.5No exploitEPSS 2%dev4press · gd star ratingJan 12, 2015
- CVE-2023-4682128Monitor
WordPress GD Security Headers Plugin <= 1.7 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%dev4press · gd security headersNov 6, 2023
- CVE-2014-283827Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack
MediumCVSS 6.8No exploitEPSS 1%dev4press · gd star ratingJan 12, 2015
- CVE-2017-1859124Monitor
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
MediumCVSS 6.1No exploitEPSS 1%dev4press · gd rating systemAug 27, 2019
- CVE-2023-312224Monitor
GD Mail Queue <= 3.9.3 - Unauthenticated Stored Cross-Site Scripting via Email
MediumCVSS 6.1No exploitEPSS 0%dev4press · gd mail queueJul 12, 2023
- CVE-2024-2509324Monitor
WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%dev4press · gd rating systemFeb 29, 2024
- CVE-2023-4033024Monitor
WordPress GD Security Headers Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%dev4press · gd security headersSep 27, 2023
- CVE-2024-086821Monitor
coreActivity < 2.1 - Unauthenticated IP Spoofing
MediumCVSS 5.3No exploitEPSS 0%dev4press · coreactivityApr 17, 2024
- CVE-2022-4581621Monitor
WordPress GD bbPress Attachments Plugin <= 4.3.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%dev4press · gd bbpress attachmentsDec 6, 2022
- CVE-2015-548118Monitor
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote att
MediumCVSS 4.3No exploitEPSS 2%dev4press · gd bbpress attachmentsAug 18, 2015
- CVE-2015-548217Monitor
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and
MediumCVSS 4.0No exploitEPSS 2%dev4press · gd bbpress attachmentsAug 18, 2015