simple-press records
6 published records for vendor simple-press.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-36706No exploit | Simple:Press – WordPress Forum Plugin <= 6.6.0 - Arbitrary File Uploadsimple-press · simple\ · CWE-434 | Critical9.8 | — | 1.8% | Oct 20, 2023 |
33Monitor | CVE-2022-4030No exploit | Simple:Press <= 6.8 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Deletionsimple-press · simple\ · CWE-22 | High8.1 | — | 1.7% | Nov 29, 2022 |
21Monitor | CVE-2022-4027No exploit | Simple:Press <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Forum Repliessimple-press · simple\ · CWE-79 | Medium5.4 | — | 0.6% | Nov 29, 2022 |
21Monitor | CVE-2022-4028No exploit | Simple:Press <= 6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Signaturessimple-press · simple\ · CWE-79 | Medium5.4 | — | 0.5% | Nov 29, 2022 |
19Monitor | CVE-2022-4031No exploit | Simple:Press <= 6.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Modificationsimple-press · simple\ · CWE-22 | Medium4.9 | — | 0.7% | Nov 29, 2022 |
18Monitor | CVE-2022-4029No exploit | Simple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie Valuesimple-press · simple\ · CWE-79 | Medium4.7 | — | 0.6% | Nov 29, 2022 |
- CVE-2020-3670640Plan
Simple:Press – WordPress Forum Plugin <= 6.6.0 - Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 2%simple-press · simple\Oct 20, 2023
- CVE-2022-403033Monitor
Simple:Press <= 6.8 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Deletion
HighCVSS 8.1No exploitEPSS 2%simple-press · simple\Nov 29, 2022
- CVE-2022-402721Monitor
Simple:Press <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Forum Replies
MediumCVSS 5.4No exploitEPSS 1%simple-press · simple\Nov 29, 2022
- CVE-2022-402821Monitor
Simple:Press <= 6.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Signatures
MediumCVSS 5.4No exploitEPSS 1%simple-press · simple\Nov 29, 2022
- CVE-2022-403119Monitor
Simple:Press <= 6.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Modification
MediumCVSS 4.9No exploitEPSS 1%simple-press · simple\Nov 29, 2022
- CVE-2022-402918Monitor
Simple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie Value
MediumCVSS 4.7No exploitEPSS 1%simple-press · simple\Nov 29, 2022