SupportCandy records
9 published records for vendor supportcandy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-1730Proof of concept | SupportCandy < 3.1.5 - Unauthenticated SQLisupportcandy · supportcandy · CWE-89 | Critical9.8 | — | 40.6% | May 2, 2023 |
42Plan | CVE-2019-11223Proof of concept | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrarsupportcandy · supportcandy · CWE-434 | Critical9.8 | — | 8.8% | Apr 18, 2019 |
35Monitor | CVE-2023-2719No exploit | SupportCandy < 3.1.7 - Subscriber+ SQLisupportcandy · supportcandy · CWE-89 | High8.8 | — | 1.2% | Jun 19, 2023 |
35Monitor | CVE-2021-24879No exploit | SupportCandy < 2.2.7 - CSRF to Cross-Site Scriptingsupportcandy · supportcandy · CWE-352 | High8.8 | — | 0.6% | Feb 7, 2022 |
30Monitor | CVE-2021-24839No exploit | SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletionsupportcandy · supportcandy · CWE-862 | High7.5 | — | 1.2% | Feb 7, 2022 |
28Monitor | CVE-2023-2805No exploit | SupportCandy < 3.1.7 - Admin+ SQLisupportcandy · supportcandy · CWE-89 | High7.2 | — | 0.9% | Jun 19, 2023 |
26Monitor | CVE-2021-24843No exploit | SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRFsupportcandy · supportcandy · CWE-352 | Medium6.5 | — | 0.5% | Feb 7, 2022 |
24Monitor | CVE-2021-24878Proof of concept | SupportCandy < 2.2.7 - Reflected Cross-Site Scriptingsupportcandy · supportcandy · CWE-79 | Medium6.1 | — | 1.2% | Feb 7, 2022 |
21Monitor | CVE-2021-24880No exploit | SupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scriptingsupportcandy · supportcandy · CWE-79 | Medium5.4 | — | 0.6% | Feb 7, 2022 |
- CVE-2023-173051Plan
SupportCandy < 3.1.5 - Unauthenticated SQLi
CriticalCVSS 9.8Proof of conceptEPSS 41%supportcandy · supportcandyMay 2, 2023
- CVE-2019-1122342Plan
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrar
CriticalCVSS 9.8Proof of conceptEPSS 9%supportcandy · supportcandyApr 18, 2019
- CVE-2023-271935Monitor
SupportCandy < 3.1.7 - Subscriber+ SQLi
HighCVSS 8.8No exploitEPSS 1%supportcandy · supportcandyJun 19, 2023
- CVE-2021-2487935Monitor
SupportCandy < 2.2.7 - CSRF to Cross-Site Scripting
HighCVSS 8.8No exploitEPSS 1%supportcandy · supportcandyFeb 7, 2022
- CVE-2021-2483930Monitor
SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletion
HighCVSS 7.5No exploitEPSS 1%supportcandy · supportcandyFeb 7, 2022
- CVE-2023-280528Monitor
SupportCandy < 3.1.7 - Admin+ SQLi
HighCVSS 7.2No exploitEPSS 1%supportcandy · supportcandyJun 19, 2023
- CVE-2021-2484326Monitor
SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF
MediumCVSS 6.5No exploitEPSS 1%supportcandy · supportcandyFeb 7, 2022
- CVE-2021-2487824Monitor
SupportCandy < 2.2.7 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 1%supportcandy · supportcandyFeb 7, 2022
- CVE-2021-2488021Monitor
SupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%supportcandy · supportcandyFeb 7, 2022