XYZScripts records
7 published records for vendor xyzscripts.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-502 Deserialization of Untrusted Data1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-36727No exploit | Newsletter Manager <= 1.5.1 - Insecure Deserializationxyzscripts · newsletter manager · CWE-502 | Critical9.8 | — | 1.6% | Jun 6, 2023 |
27Monitor | CVE-2012-6629No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attxyzscripts · newsletter manager · CWE-352 | Medium6.8 | — | 1.0% | Jan 16, 2014 |
26Monitor | CVE-2024-7420No exploit | Insert PHP Code Snippet <= 1.3.6 - Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletionxyzscripts · insert php code snippet · CWE-352 | Medium6.5 | — | 0.2% | Aug 14, 2024 |
21Monitor | CVE-2017-20054No exploit | XYZScripts Contact Form Manager Plugin cross site scritingxyzscripts · contact form manager · CWE-80 | Medium5.4 | — | 0.8% | Jun 16, 2022 |
18Monitor | CVE-2012-6628No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inxyzscripts · newsletter manager · CWE-79 | Medium4.3 | — | 2.1% | Jan 16, 2014 |
17Monitor | CVE-2012-6627No exploit | Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allows remoxyzscripts · newsletter manager · CWE-79 | Medium4.3 | — | 1.6% | Jan 16, 2014 |
17Monitor | CVE-2017-20053No exploit | XYZScripts Contact Form Manager Plugin cross-site request forgeryxyzscripts · contact form manager · CWE-352 | Medium4.3 | — | 0.6% | Jun 16, 2022 |
- CVE-2020-3672739Monitor
Newsletter Manager <= 1.5.1 - Insecure Deserialization
CriticalCVSS 9.8No exploitEPSS 2%xyzscripts · newsletter managerJun 6, 2023
- CVE-2012-662927Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote att
MediumCVSS 6.8No exploitEPSS 1%xyzscripts · newsletter managerJan 16, 2014
- CVE-2024-742026Monitor
Insert PHP Code Snippet <= 1.3.6 - Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion
MediumCVSS 6.5No exploitEPSS 0%xyzscripts · insert php code snippetAug 14, 2024
- CVE-2017-2005421Monitor
XYZScripts Contact Form Manager Plugin cross site scriting
MediumCVSS 5.4No exploitEPSS 1%xyzscripts · contact form managerJun 16, 2022
- CVE-2012-662818Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to in
MediumCVSS 4.3No exploitEPSS 2%xyzscripts · newsletter managerJan 16, 2014
- CVE-2012-662717Monitor
Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allows remo
MediumCVSS 4.3No exploitEPSS 2%xyzscripts · newsletter managerJan 16, 2014
- CVE-2017-2005317Monitor
XYZScripts Contact Form Manager Plugin cross-site request forgery
MediumCVSS 4.3No exploitEPSS 1%xyzscripts · contact form managerJun 16, 2022