Skip to content
Noroxi

usabilitydynamics records

8 published records for vendor usabilitydynamics.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 22
  3. 24

Bar: total · dark part: CISA KEV.

Attack profile

All records

8 records
  • CVE-2022-1202
    31Monitor

    WP-CRM <= 1.2.1 - CSV Injection

    HighCVSS 7.8No exploitEPSS 1%

    usabilitydynamics · wp-crmJun 13, 2022

  • The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

    MediumCVSS 6.5No exploitEPSS 1%

    usabilitydynamics · wp-invoiceSep 20, 2019

  • CVE-2022-1617
    24Monitor

    WP-Invoice <= 4.3.1 - Stored Cross-Site Scripting via CSRF

    MediumCVSS 6.1No exploitEPSS 0%

    usabilitydynamics · wp-invoiceJan 16, 2024

  • The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

    MediumCVSS 5.3No exploitEPSS 2%

    usabilitydynamics · wp-invoiceSep 20, 2019

  • The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

    MediumCVSS 5.3No exploitEPSS 2%

    usabilitydynamics · wp-invoiceSep 20, 2019

  • The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

    MediumCVSS 5.3No exploitEPSS 2%

    usabilitydynamics · wp-invoiceSep 20, 2019

  • The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

    MediumCVSS 5.3No exploitEPSS 2%

    usabilitydynamics · wp-invoiceSep 20, 2019

  • The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

    MediumCVSS 5.3No exploitEPSS 2%

    usabilitydynamics · wp-invoiceSep 20, 2019