wickedplugins records
21 published records for vendor wickedplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-862 Missing Authorization10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2021-24919No exploit | Wicked Folders < 2.18.10 - Subscriber+ SQL Injectionwickedplugins · wicked folders · CWE-89 | High8.8 | — | 1.5% | Feb 1, 2022 |
17Monitor | CVE-2023-0719No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_sort_orderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0712No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_move_objectwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0718No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0716No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_edit_folderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0713No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_add_folderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0717No exploit | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_delete_folderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0684No exploit | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_unassign_folderswickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0720No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder_orderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0715No exploit | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_clone_folderwickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0711No exploit | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_save_statewickedplugins · wicked folders · CWE-862 | Medium4.3 | — | 0.6% | Feb 7, 2023 |
17Monitor | CVE-2023-0730No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_folder_orderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0723No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_move_objectwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0727No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_delete_folderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0728No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_save_folderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0685No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_unassign_folderswickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0722No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_statewickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0724No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_add_folderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0725No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_clone_folderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0726No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_edit_folderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Feb 7, 2023 |
17Monitor | CVE-2023-0729No exploit | Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_sort_orderwickedplugins · wicked folders · CWE-352 | Medium4.3 | — | 0.3% | Jun 9, 2023 |
- CVE-2021-2491935Monitor
Wicked Folders < 2.18.10 - Subscriber+ SQL Injection
HighCVSS 8.8No exploitEPSS 2%wickedplugins · wicked foldersFeb 1, 2022
- CVE-2023-071917Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_sort_order
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071217Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_move_object
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071817Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071617Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_edit_folder
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071317Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_add_folder
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071717Monitor
Wicked Folders <= 2.18.16 - Missing Authorization via ajax_delete_folder
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-068417Monitor
Wicked Folders <= 2.18.16 - Missing Authorization via ajax_unassign_folders
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072017Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder_order
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071517Monitor
Wicked Folders <= 2.18.16 - Missing Authorization on ajax_clone_folder
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-071117Monitor
Wicked Folders <= 2.18.16 - Missing Authorization via ajax_save_state
MediumCVSS 4.3No exploitEPSS 1%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-073017Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_folder_order
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072317Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_move_object
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072717Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_delete_folder
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072817Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery on ajax_save_folder
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-068517Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_unassign_folders
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072217Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_state
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072417Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_add_folder
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072517Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_clone_folder
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072617Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_edit_folder
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersFeb 7, 2023
- CVE-2023-072917Monitor
Wicked Folders <= 2.18.16 - Cross-Site Request Forgery via ajax_save_sort_order
MediumCVSS 4.3No exploitEPSS 0%wickedplugins · wicked foldersJun 9, 2023