elearningfreak records
6 published records for vendor elearningfreak.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2019-15649No exploit | The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.elearningfreak · insert or embed articulate content · CWE-434 | High8.8 | — | 1.7% | Aug 27, 2019 |
35Monitor | CVE-2024-5630No exploit | Insert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File Uploadelearningfreak · insert or embed articulate content · CWE-434 | High8.8 | — | 0.7% | Jul 15, 2024 |
26Monitor | CVE-2019-15648No exploit | The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renamelearningfreak · insert or embed articulate content · CWE-22 | Medium6.5 | — | 0.6% | Aug 27, 2019 |
21Monitor | CVE-2024-0757Proof of concept | Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Author+ Upload to RCEelearningfreak · insert or embed articulate content · CWE-434 | Medium5.4 | — | 0.9% | Jun 4, 2024 |
21Monitor | CVE-2023-50824No exploit | WordPress Insert or Embed Articulate Content into WordPress Plugin <= 4.3000000021 is vulnerable to Cross Site Scripting (XSS)elearningfreak · insert or embed articulate content · CWE-79 | Medium5.4 | — | 0.3% | Dec 21, 2023 |
21Monitor | CVE-2024-0756No exploit | Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Iframe Injectionelearningfreak · insert or embed articulate content · CWE-79 | Medium5.4 | — | 0.2% | Jun 4, 2024 |
- CVE-2019-1564936Monitor
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
HighCVSS 8.8No exploitEPSS 2%elearningfreak · insert or embed articulate contentAug 27, 2019
- CVE-2024-563035Monitor
Insert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%elearningfreak · insert or embed articulate contentJul 15, 2024
- CVE-2019-1564826Monitor
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renam
MediumCVSS 6.5No exploitEPSS 1%elearningfreak · insert or embed articulate contentAug 27, 2019
- CVE-2024-075721Monitor
Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Author+ Upload to RCE
MediumCVSS 5.4Proof of conceptEPSS 1%elearningfreak · insert or embed articulate contentJun 4, 2024
- CVE-2023-5082421Monitor
WordPress Insert or Embed Articulate Content into WordPress Plugin <= 4.3000000021 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%elearningfreak · insert or embed articulate contentDec 21, 2023
- CVE-2024-075621Monitor
Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Iframe Injection
MediumCVSS 5.4No exploitEPSS 0%elearningfreak · insert or embed articulate contentJun 4, 2024