Skip to content
Noroxi

spiffyplugins records

13 published records for vendor spiffyplugins.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
84.6%
Median publish → KEV
No record has entered KEV

All records

13 records
  • WordPress Spiffy Calendar Plugin <= 4.9.1 is vulnerable to SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    spiffyplugins · spiffy calendarNov 3, 2023

  • WordPress spiffy-calendar plugin <= 4.9.11 - SQL Injection vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    spiffyplugins · spiffy calendarJul 22, 2024

  • WordPress Spiffy Calendar plugin <= 4.9.10 - Broken Access Control vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    spiffyplugins · spiffy calendarJun 4, 2024

  • WordPress Spiffy Calendar plugin <= 4.9.7 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    spiffyplugins · spiffy calendarMar 29, 2024

  • WordPress Spiffy Calendar Plugin <= 4.9.3 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    spiffyplugins · spiffy calendarAug 18, 2023

  • WordPress Spiffy Calendar plugin <= 4.9.13 - Reflected Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    spiffyplugins · spiffy calendarSep 15, 2024

  • WordPress Spiffy Calendar plugin <= 4.9.0 - Edit/Delete event via IDOR vulnerability

    MediumCVSS 5.4No exploitEPSS 1%

    spiffyplugins · spiffy calendarMay 20, 2022

  • CVE-2024-0855
    21Monitor

    Spiffy Calendar < 4.9.9 - Broken Access Control

    MediumCVSS 5.3No exploitEPSS 0%

    spiffyplugins · spiffy calendarFeb 27, 2024

  • WordPress Spiffy Calendar Plugin <= 4.9.5 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    spiffyplugins · spiffy calendarDec 14, 2023

  • WordPress WP Flow Plus plugin <= 5.2.3 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    spiffyplugins · wp flow plusOct 24, 2024

  • WordPress Spiffy Calendar plugin <= 4.9.13 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    spiffyplugins · spiffy calendarSep 15, 2024

  • WordPress WP Flow Plus plugin <= 5.2.2 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 5.4No exploitEPSS 0%

    spiffyplugins · wp flow plusJun 4, 2024

  • WordPress Spiffy Calendar plugin <= 4.9.0 - Event deletion via Cross-Site Request Forgery (CSRF) vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    spiffyplugins · spiffy calendarFeb 21, 2022