TablePress records
7 published records for vendor tablepress.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2019-20180No exploit | The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users.tablepress · tablepress · CWE-1236 | Medium6.8 | — | 2.3% | Jan 9, 2020 |
25Monitor | CVE-2024-4354No exploit | TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebindtablepress · tablepress · CWE-918 | Medium6.4 | — | 0.4% | Jun 7, 2024 |
21Monitor | CVE-2025-5096No exploit | TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameterstablepress · tablepress · CWE-79 | Medium5.4 | — | 0.4% | May 23, 2025 |
21Monitor | CVE-2024-9595No exploit | TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scriptingtablepress · tablepress · CWE-79 | Medium5.4 | — | 0.3% | Oct 12, 2024 |
21Monitor | CVE-2025-2685No exploit | TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scriptingtablepress · tablepress · CWE-79 | Medium5.4 | — | 0.3% | Mar 27, 2025 |
19Monitor | CVE-2024-23825No exploit | TablePress SSRF vulnerability due to insufficient filtering of cloud provider hoststablepress · tablepress · CWE-918 | Medium4.9 | — | 0.5% | Jan 30, 2024 |
17Monitor | CVE-2017-10889No exploit | TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.tablepress · tablepress · CWE-611 | Medium4.3 | — | 1.1% | Nov 17, 2017 |
- CVE-2019-2018028Monitor
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users.
MediumCVSS 6.8No exploitEPSS 2%tablepress · tablepressJan 9, 2020
- CVE-2024-435425Monitor
TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind
MediumCVSS 6.4No exploitEPSS 0%tablepress · tablepressJun 7, 2024
- CVE-2025-509621Monitor
TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters
MediumCVSS 5.4No exploitEPSS 0%tablepress · tablepressMay 23, 2025
- CVE-2024-959521Monitor
TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%tablepress · tablepressOct 12, 2024
- CVE-2025-268521Monitor
TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%tablepress · tablepressMar 27, 2025
- CVE-2024-2382519Monitor
TablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts
MediumCVSS 4.9No exploitEPSS 1%tablepress · tablepressJan 30, 2024
- CVE-2017-1088917Monitor
TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
MediumCVSS 4.3No exploitEPSS 1%tablepress · tablepressNov 17, 2017