Sumo records
7 published records for vendor sumo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-502 Deserialization of Untrusted Data2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2015-4697No exploit | Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.sumo · google analyticator · CWE-352 | High8.8 | — | 1.2% | Sep 7, 2017 |
35Monitor | CVE-2023-25033No exploit | WordPress Social Share Boost Plugin <= 4.5 is vulnerable to Cross Site Request Forgery (CSRF)sumo · social share boost · CWE-352 | High8.8 | — | 0.2% | Oct 6, 2023 |
28Monitor | CVE-2022-4323No exploit | Google Analyticator < 6.5.6 - Admin+ PHP Object Injectionsumo · google analyticator · CWE-502 | High7.2 | — | 1.0% | Jan 23, 2023 |
28Monitor | CVE-2022-3425No exploit | Google Analyticator < 6.5.6 - Admin+ PHP Object Injectionsumo · google analyticator · CWE-502 | High7.2 | — | 1.0% | Jan 23, 2023 |
24Monitor | CVE-2009-5158No exploit | The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.sumo · google analyticator · CWE-20 | Medium6.1 | — | 0.9% | Aug 22, 2019 |
21Monitor | CVE-2023-23688No exploit | WordPress Social Share Boost Plugin <= 4.4 is vulnerable to Cross Site Scripting (XSS)sumo · social share boost · CWE-79 | Medium5.4 | — | 0.4% | May 15, 2023 |
19Monitor | CVE-2023-25044No exploit | WordPress Social Share Boost Plugin <= 4.4 is vulnerable to Cross Site Scripting (XSS)sumo · social share boost · CWE-79 | Medium4.8 | — | 0.4% | Sep 1, 2023 |
- CVE-2015-469735Monitor
Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.
HighCVSS 8.8No exploitEPSS 1%sumo · google analyticatorSep 7, 2017
- CVE-2023-2503335Monitor
WordPress Social Share Boost Plugin <= 4.5 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%sumo · social share boostOct 6, 2023
- CVE-2022-432328Monitor
Google Analyticator < 6.5.6 - Admin+ PHP Object Injection
HighCVSS 7.2No exploitEPSS 1%sumo · google analyticatorJan 23, 2023
- CVE-2022-342528Monitor
Google Analyticator < 6.5.6 - Admin+ PHP Object Injection
HighCVSS 7.2No exploitEPSS 1%sumo · google analyticatorJan 23, 2023
- CVE-2009-515824Monitor
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
MediumCVSS 6.1No exploitEPSS 1%sumo · google analyticatorAug 22, 2019
- CVE-2023-2368821Monitor
WordPress Social Share Boost Plugin <= 4.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%sumo · social share boostMay 15, 2023
- CVE-2023-2504419Monitor
WordPress Social Share Boost Plugin <= 4.4 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%sumo · social share boostSep 1, 2023