Skip to content
Noroxi

plugin records

14 published records for vendor plugin.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

14 records
  • The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc

    HighCVSS 8.8No exploitEPSS 1%

    plugin · waitingMar 22, 2023

  • CVE-2023-1865
    26Monitor

    YourChannel <= 1.2.3 - Missing Authorization to Plugin Settings Reset

    MediumCVSS 6.5No exploitEPSS 1%

    plugin · yourchannelApr 5, 2023

  • CVE-2023-1868
    21Monitor

    YourChannel <= 1.2.3 - Missing Authorization to Plugin Cache Reset

    MediumCVSS 5.3No exploitEPSS 1%

    plugin · yourchannelApr 5, 2023

  • CVE-2022-4833
    21Monitor

    YourChannel: Everything you want in a YouTube plugin < 1.2.3 - Contributor+ Stored XSS via Shortcode

    MediumCVSS 5.4No exploitEPSS 1%

    plugin · yourchannelFeb 6, 2023

  • CVE-2023-0282
    21Monitor

    YourChannel < 1.2.2 - Subscriber+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 1%

    plugin · yourchannelFeb 6, 2023

  • CVE-2023-2757
    21Monitor

    Waiting: One-click countdowns <= 0.6.2 - Missing Authorization Checks leading to Authenticated (Subscriber+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    plugin · waitingMay 17, 2023

  • CVE-2023-1869
    19Monitor

    YourChannel <= 1.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 0%

    plugin · yourchannelApr 5, 2023

  • CVE-2022-4954
    19Monitor

    Waiting: One-click countdowns <= 0.6.2 - Authenticated (Administrator+) Cross-Site Scripting

    MediumCVSS 4.8No exploitEPSS 0%

    plugin · waitingOct 20, 2023

  • CVE-2023-3999
    17Monitor

    Waiting: One-click countdowns <= 0.6.2 - Missing Authorization

    MediumCVSS 4.3No exploitEPSS 0%

    plugin · waitingAug 31, 2023

  • CVE-2023-1870
    17Monitor

    YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Update

    MediumCVSS 4.3No exploitEPSS 0%

    plugin · yourchannelApr 5, 2023

  • CVE-2023-1867
    17Monitor

    YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Settings Change

    MediumCVSS 4.3No exploitEPSS 0%

    plugin · yourchannelApr 5, 2023

  • CVE-2023-1866
    17Monitor

    YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Channel Reset

    MediumCVSS 4.3No exploitEPSS 0%

    plugin · yourchannelApr 5, 2023

  • CVE-2023-1871
    17Monitor

    YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Reset

    MediumCVSS 4.3No exploitEPSS 0%

    plugin · yourchannelApr 5, 2023

  • CVE-2023-4000
    17Monitor

    Waiting: One-click countdowns <= 0.6.2 - Cross-Site Request Forgery

    MediumCVSS 4.3No exploitEPSS 0%

    plugin · waitingAug 31, 2023