talkback records
5 published records for vendor talkback.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-502 Deserialization of Untrusted Data1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-48033No exploit | WordPress Talkback plugin <= 1.0 - PHP Object Injection vulnerabilitybaptiste.gourdin · talkback · CWE-502 | Critical9.8 | — | 0.6% | Oct 11, 2024 |
31Monitor | CVE-2008-3371Proof of concept | Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to inclutalkback · talkback · CWE-22 | High7.5 | — | 3.5% | Jul 30, 2008 |
31Monitor | CVE-2008-4346Proof of concept | Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .talkback · talkback · CWE-22 | High7.5 | — | 2.8% | Sep 30, 2008 |
29Monitor | CVE-2007-6105Proof of concept | Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (talkback · talkback · CWE-94 | Medium6.8 | — | 6.7% | Nov 23, 2007 |
21Monitor | CVE-2008-4115Proof of concept | TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfotalkback · talkback · CWE-200 | Medium5.0 | — | 2.6% | Sep 16, 2008 |
- CVE-2024-4803339Monitor
WordPress Talkback plugin <= 1.0 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%baptiste.gourdin · talkbackOct 11, 2024
- CVE-2008-337131Monitor
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to inclu
HighCVSS 7.5Proof of conceptEPSS 4%talkback · talkbackJul 30, 2008
- CVE-2008-434631Monitor
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .
HighCVSS 7.5Proof of conceptEPSS 3%talkback · talkbackSep 30, 2008
- CVE-2007-610529Monitor
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (
MediumCVSS 6.8Proof of conceptEPSS 7%talkback · talkbackNov 23, 2007
- CVE-2008-411521Monitor
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo
MediumCVSS 5.0Proof of conceptEPSS 3%talkback · talkbackSep 16, 2008