Skip to content
Noroxi

SupportCandy records

9 published records for vendor supportcandy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • SupportCandy < 3.1.5 - Unauthenticated SQLi

    CriticalCVSS 9.8Proof of conceptEPSS 41%

    supportcandy · supportcandyMay 2, 2023

  • An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrar

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    supportcandy · supportcandyApr 18, 2019

  • CVE-2023-2719
    35Monitor

    SupportCandy < 3.1.7 - Subscriber+ SQLi

    HighCVSS 8.8No exploitEPSS 1%

    supportcandy · supportcandyJun 19, 2023

  • SupportCandy < 2.2.7 - CSRF to Cross-Site Scripting

    HighCVSS 8.8No exploitEPSS 1%

    supportcandy · supportcandyFeb 7, 2022

  • SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletion

    HighCVSS 7.5No exploitEPSS 1%

    supportcandy · supportcandyFeb 7, 2022

  • CVE-2023-2805
    28Monitor

    SupportCandy < 3.1.7 - Admin+ SQLi

    HighCVSS 7.2No exploitEPSS 1%

    supportcandy · supportcandyJun 19, 2023

  • SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF

    MediumCVSS 6.5No exploitEPSS 1%

    supportcandy · supportcandyFeb 7, 2022

  • SupportCandy < 2.2.7 - Reflected Cross-Site Scripting

    MediumCVSS 6.1Proof of conceptEPSS 1%

    supportcandy · supportcandyFeb 7, 2022

  • SupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 1%

    supportcandy · supportcandyFeb 7, 2022