webcraftplugins records
4 published records for vendor webcraftplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2023-3412No exploit | Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite <= 1.0.0 - Missing Authorization to Stored Cross-Site Scriptingwebcraftplugins · image map pro · CWE-79 | Medium5.4 | — | 0.3% | Jun 27, 2023 |
21Monitor | CVE-2024-9584No exploit | Image Map Pro <= 6.0.20 - Missing Authorization to Authenticated (Contributor+) Map Project Add/Update/Deletewebcraftplugins · image map pro · CWE-862 | Medium5.4 | — | 0.3% | Oct 25, 2024 |
21Monitor | CVE-2024-9585No exploit | Image Map Pro <= 6.0.20 - Authenticated (Contributor+) Stored Cross-Site Scriptingwebcraftplugins · image map pro · CWE-79 | Medium5.4 | — | 0.3% | Oct 25, 2024 |
17Monitor | CVE-2023-3411No exploit | Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scriptingwebcraftplugins · image map pro · CWE-352 | Medium4.3 | — | 0.3% | Jun 27, 2023 |
- CVE-2023-341221Monitor
Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite <= 1.0.0 - Missing Authorization to Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%webcraftplugins · image map proJun 27, 2023
- CVE-2024-958421Monitor
Image Map Pro <= 6.0.20 - Missing Authorization to Authenticated (Contributor+) Map Project Add/Update/Delete
MediumCVSS 5.4No exploitEPSS 0%webcraftplugins · image map proOct 25, 2024
- CVE-2024-958521Monitor
Image Map Pro <= 6.0.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%webcraftplugins · image map proOct 25, 2024
- CVE-2023-341117Monitor
Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
MediumCVSS 4.3No exploitEPSS 0%webcraftplugins · image map proJun 27, 2023