Skip to content
Noroxi

verbb records

10 published records for vendor verbb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

10 records
  • The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

    CriticalCVSS 9.1No exploitEPSS 1%

    verbb · knock knockMay 25, 2020

  • An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS.

    HighCVSS 8.8No exploitEPSS 0%

    verbb · image resizerMay 25, 2020

  • An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS.

    MediumCVSS 6.5No exploitEPSS 0%

    verbb · commentsJun 5, 2020

  • The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.

    MediumCVSS 6.1No exploitEPSS 1%

    verbb · knock knockMay 25, 2020

  • An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS.

    MediumCVSS 5.4No exploitEPSS 1%

    verbb · commentsJun 5, 2020

  • An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS.

    MediumCVSS 5.4No exploitEPSS 1%

    verbb · image resizerMay 25, 2020

  • An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS.

    MediumCVSS 5.4No exploitEPSS 1%

    verbb · commentsJun 5, 2020

  • Formie has a XSS vulnerability for importing forms

    MediumCVSS 5.3No exploitEPSS 0%

    verbb · formieApr 11, 2025

  • Formie has a XSS vulnerability for email notification content for preview

    MediumCVSS 5.4No exploitEPSS 0%

    verbb · formieApr 11, 2025

  • verbb/formie Server-Side Template Injection for variable-enabled settings

    MediumCVSS 4.4No exploitEPSS 0%

    verbb · formieMay 20, 2024