scriptsbundle records
6 published records for vendor scriptsbundle.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-288 Authentication Bypass Using an Alternate Path or Channel2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-11349No exploit | AdForest <= 5.1.6 - Authentication Bypassscriptsbundle · adforest · CWE-288 | Critical9.8 | — | 1.2% | Dec 21, 2024 |
39Monitor | CVE-2024-12857No exploit | AdForest <= 5.1.8 - Authentication Bypassscriptsbundle · adforest · CWE-288 | Critical9.8 | — | 0.7% | Jan 22, 2025 |
39Monitor | CVE-2024-11350No exploit | AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeoverscriptsbundle · adforest · CWE-640 | Critical9.8 | — | 0.7% | Jan 8, 2025 |
21Monitor | CVE-2019-15870No exploit | The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.scriptsbundle · carspot · CWE-79 | Medium5.4 | — | 0.7% | Sep 3, 2019 |
21Monitor | CVE-2025-0169No exploit | DWT - Directory & Listing WordPress Theme <=3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodescriptsbundle · dwt listing · CWE-79 | Medium5.4 | — | 0.3% | Feb 8, 2025 |
21Monitor | CVE-2024-12855No exploit | AdForest - Classified Ads WordPress Theme <= 5.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post/Attachment Deletionscriptsbundle · adforest · CWE-862 | Medium5.4 | — | 0.3% | Jan 8, 2025 |
- CVE-2024-1134939Monitor
AdForest <= 5.1.6 - Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 1%scriptsbundle · adforestDec 21, 2024
- CVE-2024-1285739Monitor
AdForest <= 5.1.8 - Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 1%scriptsbundle · adforestJan 22, 2025
- CVE-2024-1135039Monitor
AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover
CriticalCVSS 9.8No exploitEPSS 1%scriptsbundle · adforestJan 8, 2025
- CVE-2019-1587021Monitor
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
MediumCVSS 5.4No exploitEPSS 1%scriptsbundle · carspotSep 3, 2019
- CVE-2025-016921Monitor
DWT - Directory & Listing WordPress Theme <=3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%scriptsbundle · dwt listingFeb 8, 2025
- CVE-2024-1285521Monitor
AdForest - Classified Ads WordPress Theme <= 5.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post/Attachment Deletion
MediumCVSS 5.4No exploitEPSS 0%scriptsbundle · adforestJan 8, 2025