Skip to content
Noroxi

TablePress records

7 published records for vendor tablepress.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
14.3%
Median publish → KEV
No record has entered KEV

All records

7 records
  • The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users.

    MediumCVSS 6.8No exploitEPSS 2%

    tablepress · tablepressJan 9, 2020

  • CVE-2024-4354
    25Monitor

    TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind

    MediumCVSS 6.4No exploitEPSS 0%

    tablepress · tablepressJun 7, 2024

  • CVE-2025-5096
    21Monitor

    TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters

    MediumCVSS 5.4No exploitEPSS 0%

    tablepress · tablepressMay 23, 2025

  • CVE-2024-9595
    21Monitor

    TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    tablepress · tablepressOct 12, 2024

  • CVE-2025-2685
    21Monitor

    TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting

    MediumCVSS 5.4No exploitEPSS 0%

    tablepress · tablepressMar 27, 2025

  • TablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts

    MediumCVSS 4.9No exploitEPSS 1%

    tablepress · tablepressJan 30, 2024

  • TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.

    MediumCVSS 4.3No exploitEPSS 1%

    tablepress · tablepressNov 17, 2017