Inpsyde records
6 published records for vendor inpsyde.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-256 Plaintext Storage of a Password1
- CWE-548 Exposure of Information Through Directory Listing1
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2023-5504No exploit | BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversalinpsyde · backwpup · CWE-22 | High8.7 | — | 0.9% | Jan 11, 2024 |
31Monitor | CVE-2023-7164Proof of concept | BackWPup < 4.0.4 - Unauthenticated Backup Downloadinpsyde · backwpup · CWE-548 | High7.5 | — | 2.3% | Apr 8, 2024 |
31Monitor | CVE-2017-2551No exploit | Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.inpsyde · backwpup · CWE-552 | High7.5 | — | 1.7% | Sep 27, 2017 |
27Monitor | CVE-2023-5505No exploit | BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversalinpsyde · backwpup · CWE-22 | Medium6.8 | — | 1.0% | Aug 17, 2024 |
24Monitor | CVE-2021-25071No exploit | Akismet Privacy Policies <= 2.0.1 - Reflected Cross-Site Scriptinginpsyde · akismet privacy policies · CWE-79 | Medium6.1 | — | 0.8% | Mar 28, 2022 |
10Monitor | CVE-2023-5775No exploit | BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Passwordinpsyde · backwpup · CWE-256 | Low2.7 | — | 0.4% | Feb 26, 2024 |
- CVE-2023-550434Monitor
BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal
HighCVSS 8.7No exploitEPSS 1%inpsyde · backwpupJan 11, 2024
- CVE-2023-716431Monitor
BackWPup < 4.0.4 - Unauthenticated Backup Download
HighCVSS 7.5Proof of conceptEPSS 2%inpsyde · backwpupApr 8, 2024
- CVE-2017-255131Monitor
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.
HighCVSS 7.5No exploitEPSS 2%inpsyde · backwpupSep 27, 2017
- CVE-2023-550527Monitor
BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal
MediumCVSS 6.8No exploitEPSS 1%inpsyde · backwpupAug 17, 2024
- CVE-2021-2507124Monitor
Akismet Privacy Policies <= 2.0.1 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%inpsyde · akismet privacy policiesMar 28, 2022
- CVE-2023-577510Monitor
BackWPup <= 4.0.2 - Plaintext Storage of Backup Destination Password
LowCVSS 2.7No exploitEPSS 0%inpsyde · backwpupFeb 26, 2024