pixelgrade records
11 published records for vendor pixelgrade.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 36.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)5
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-27633No exploit | WordPress Customify Plugin <= 2.10.4 is vulnerable to Cross Site Request Forgery (CSRF)pixelgrade · customify · CWE-352 | High8.8 | — | 0.3% | Nov 22, 2023 |
35Monitor | CVE-2023-23704No exploit | WordPress Comments Ratings Plugin <= 1.1.6 is vulnerable to Cross Site Request Forgery (CSRF)pixelgrade · comments rating · CWE-352 | High8.8 | — | 0.3% | Jul 11, 2023 |
35Monitor | CVE-2023-25487No exploit | WordPress PixTypes Plugin <= 1.4.14 is vulnerable to Cross Site Request Forgery (CSRF)pixelgrade · pixtypes · CWE-352 | High8.8 | — | 0.3% | Jul 11, 2023 |
35Monitor | CVE-2023-45655No exploit | WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Request Forgery (CSRF)pixelgrade · pixfields · CWE-352 | High8.8 | — | 0.2% | Oct 16, 2023 |
35Monitor | CVE-2023-45654No exploit | WordPress Comments Ratings Plugin <= 1.1.7 is vulnerable to Cross Site Request Forgery (CSRF)pixelgrade · comments rating · CWE-352 | High8.8 | — | 0.2% | Oct 16, 2023 |
24Monitor | CVE-2023-40205No exploit | WordPress PixTypes Plugin <= 1.4.15 is vulnerable to Cross Site Scripting (XSS)pixelgrade · pixtypes · CWE-79 | Medium6.1 | — | 0.4% | Sep 4, 2023 |
21Monitor | CVE-2022-4671No exploit | PixCodes < 2.3.7 - Contributor+ Stored XSS in Shortcodepixelgrade · pixcodes · CWE-79 | Medium5.4 | — | 0.5% | Jan 30, 2023 |
21Monitor | CVE-2024-8241No exploit | Nova Blocks by Pixelgrade <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attributepixelgrade · nova blocks · CWE-79 | Medium5.4 | — | 0.4% | Sep 10, 2024 |
21Monitor | CVE-2022-46844No exploit | WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Scripting (XSS)pixelgrade · pixfields · CWE-79 | Medium5.4 | — | 0.4% | May 9, 2023 |
21Monitor | CVE-2024-12813No exploit | Open Hours – Easy Opening Hours <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scriptingpixelgrade · open hours · CWE-79 | Medium5.4 | — | 0.3% | Feb 18, 2025 |
19Monitor | CVE-2023-23702No exploit | WordPress Comments Ratings Plugin <= 1.1.7 is vulnerable to Cross Site Scripting (XSS)pixelgrade · comments rating · CWE-79 | Medium4.8 | — | 0.3% | Nov 6, 2023 |
- CVE-2023-2763335Monitor
WordPress Customify Plugin <= 2.10.4 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%pixelgrade · customifyNov 22, 2023
- CVE-2023-2370435Monitor
WordPress Comments Ratings Plugin <= 1.1.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%pixelgrade · comments ratingJul 11, 2023
- CVE-2023-2548735Monitor
WordPress PixTypes Plugin <= 1.4.14 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%pixelgrade · pixtypesJul 11, 2023
- CVE-2023-4565535Monitor
WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%pixelgrade · pixfieldsOct 16, 2023
- CVE-2023-4565435Monitor
WordPress Comments Ratings Plugin <= 1.1.7 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%pixelgrade · comments ratingOct 16, 2023
- CVE-2023-4020524Monitor
WordPress PixTypes Plugin <= 1.4.15 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%pixelgrade · pixtypesSep 4, 2023
- CVE-2022-467121Monitor
PixCodes < 2.3.7 - Contributor+ Stored XSS in Shortcode
MediumCVSS 5.4No exploitEPSS 0%pixelgrade · pixcodesJan 30, 2023
- CVE-2024-824121Monitor
Nova Blocks by Pixelgrade <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute
MediumCVSS 5.4No exploitEPSS 0%pixelgrade · nova blocksSep 10, 2024
- CVE-2022-4684421Monitor
WordPress PixFields Plugin <= 0.7.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%pixelgrade · pixfieldsMay 9, 2023
- CVE-2024-1281321Monitor
Open Hours – Easy Opening Hours <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%pixelgrade · open hoursFeb 18, 2025
- CVE-2023-2370219Monitor
WordPress Comments Ratings Plugin <= 1.1.7 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%pixelgrade · comments ratingNov 6, 2023