tri records
9 published records for vendor tri.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 11.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-707 Improper Neutralization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-0381No exploit | GigPress <= 2.3.28 - Subscriber+ SQLitri · gigpress · CWE-89 | High8.8 | — | 1.3% | Feb 27, 2023 |
28Monitor | CVE-2015-9353No exploit | The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066.tri · gigpress · CWE-89 | High7.2 | — | 1.4% | Aug 28, 2019 |
27Monitor | CVE-2015-4066Proof of concept | Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated ustri · gigpress · CWE-89 | Medium6.5 | — | 4.2% | May 27, 2015 |
26Monitor | CVE-2024-1295No exploit | The Events Calendar (Free < 6.4.0.1, Pro < 6.4.0.1) - Contributor+ Arbitrary Events Accesstri · the events calendar · CWE-639 | Medium6.5 | — | 0.5% | Jun 14, 2024 |
25Monitor | CVE-2021-25028Proof of concept | Event Tickets < 5.2.2 - Open Redirecttri · event tickets · CWE-601 | Medium6.1 | — | 1.9% | Jan 24, 2022 |
24Monitor | CVE-2020-36626No exploit | Modern Tribe Panel Builder Plugin SearchFilter.php add_post_content_filtered_to_search_sql sql injectiontri · panel builder · CWE-707 | Medium6.1 | — | 0.6% | Dec 27, 2022 |
21Monitor | CVE-2022-4759No exploit | GigPress < 2.3.28 - Contributor+ Stored XSS via Shortcodetri · gigpress · CWE-79 | Medium5.4 | — | 0.7% | Feb 13, 2023 |
19Monitor | CVE-2015-9354No exploit | The gigpress plugin before 2.3.11 for WordPress has XSS.tri · gigpress · CWE-79 | Medium4.8 | — | 0.7% | Aug 28, 2019 |
19Monitor | CVE-2023-7233No exploit | GigPress <= 2.3.29 - Admin+ Stored Cross Site Scriptingtri · gigpress · CWE-79 | Medium4.8 | — | 0.5% | Feb 12, 2024 |
- CVE-2023-038135Monitor
GigPress <= 2.3.28 - Subscriber+ SQLi
HighCVSS 8.8No exploitEPSS 1%tri · gigpressFeb 27, 2023
- CVE-2015-935328Monitor
The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066.
HighCVSS 7.2No exploitEPSS 1%tri · gigpressAug 28, 2019
- CVE-2015-406627Monitor
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated us
MediumCVSS 6.5Proof of conceptEPSS 4%tri · gigpressMay 27, 2015
- CVE-2024-129526Monitor
The Events Calendar (Free < 6.4.0.1, Pro < 6.4.0.1) - Contributor+ Arbitrary Events Access
MediumCVSS 6.5No exploitEPSS 0%tri · the events calendarJun 14, 2024
- CVE-2021-2502825Monitor
Event Tickets < 5.2.2 - Open Redirect
MediumCVSS 6.1Proof of conceptEPSS 2%tri · event ticketsJan 24, 2022
- CVE-2020-3662624Monitor
Modern Tribe Panel Builder Plugin SearchFilter.php add_post_content_filtered_to_search_sql sql injection
MediumCVSS 6.1No exploitEPSS 1%tri · panel builderDec 27, 2022
- CVE-2022-475921Monitor
GigPress < 2.3.28 - Contributor+ Stored XSS via Shortcode
MediumCVSS 5.4No exploitEPSS 1%tri · gigpressFeb 13, 2023
- CVE-2015-935419Monitor
The gigpress plugin before 2.3.11 for WordPress has XSS.
MediumCVSS 4.8No exploitEPSS 1%tri · gigpressAug 28, 2019
- CVE-2023-723319Monitor
GigPress <= 2.3.29 - Admin+ Stored Cross Site Scripting
MediumCVSS 4.8No exploitEPSS 0%tri · gigpressFeb 12, 2024