Cat (Patchstack Alliance)
39 записей с упоминанием · 0 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
21Наблюдать | CVE-2022-47601Эксплойта нет | WordPress WP Table Manager plugin <= 3.5.2 - Broken Access Controljoomunited · wp table manager · CWE-862 | Средняя5,3 | — | 0,4 % | 2 янв. 2025 г. |
17Наблюдать | CVE-2023-39994Эксплойта нет | WordPress ARMember Premium plugin <= 5.9.2 - Broken Access Controlreputeinfosystems · armember · CWE-862 | Средняя4,3 | — | 0,3 % | 2 янв. 2025 г. |
21Наблюдать | CVE-2023-39996Эксплойта нет | WordPress Accordion and Accordion Slider plugin <= 1.2.4 - Broken Access Controlwp onlinesupport, essential plugin · accordion and accordion slider · CWE-862 | Средняя5,3 | — | 0,5 % | 13 дек. 2024 г. |
17Наблюдать | CVE-2023-39995Эксплойта нет | WordPress Portfolio and Projects plugin <= 1.3.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · portfolio and projects · CWE-862 | Средняя4,3 | — | 0,5 % | 13 дек. 2024 г. |
21Наблюдать | CVE-2023-36519Эксплойта нет | WordPress SW Product Bundles plugin <= 2.0.15 - Broken Access Control vulnerabilitywpthemego · sw product bundles · CWE-862 | Средняя5,4 | — | 0,6 % | 13 дек. 2024 г. |
17Наблюдать | CVE-2023-36518Эксплойта нет | WordPress Post Hit Counter plugin <= 1.3.2 - Broken Access Controlhugh lashbrooke · post hit counter · CWE-862 | Средняя4,3 | — | 0,5 % | 13 дек. 2024 г. |
21Наблюдать | CVE-2022-47182Эксплойта нет | WordPress APIExperts Square for WooCommerce plugin <= 4.4.1 - Broken Access Controlwpexpertsio · apiexperts square for woocommerce · CWE-862 | Средняя5,3 | — | 0,5 % | 13 дек. 2024 г. |
21Наблюдать | CVE-2022-46846Эксплойта нет | WordPress Trending/Popular Post Slider and Widget plugin <= 1.5.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · trending/popular post slider and widget · CWE-862 | Средняя5,3 | — | 0,5 % | 13 дек. 2024 г. |
17Наблюдать | CVE-2022-46811Эксплойта нет | WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRFvillatheme(villatheme.com) · ald – dropshipping and fulfillment for aliexpress and woocommerce · CWE-862 | Средняя4,3 | — | 0,5 % | 13 дек. 2024 г. |
17Наблюдать | CVE-2022-46807Эксплойта нет | WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Controllauri karisola / wp trio · stock sync for woocommerce · CWE-862 | Средняя4,3 | — | 0,5 % | 13 дек. 2024 г. |
21Наблюдать | CVE-2023-30488Эксплойта нет | WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · featured post creative · CWE-862 | Средняя5,3 | — | 0,4 % | 9 дек. 2024 г. |
21Наблюдать | CVE-2023-25703Эксплойта нет | WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · meta slider and carousel with lightbox · CWE-862 | Средняя5,3 | — | 0,5 % | 9 дек. 2024 г. |
21Наблюдать | CVE-2023-25060Эксплойта нет | WordPress Album and Image Gallery plus Lightbox plugin <= 1.6.2 - Broken Access Control vulnerabilitywp onlinesupport, essential plugin · album and image gallery plus lightbox · CWE-862 | Средняя5,3 | — | 0,6 % | 9 дек. 2024 г. |
21Наблюдать | CVE-2023-23868Эксплойта нет | WordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerabilitywpfactory · cost of goods for woocommerce · CWE-862 | Средняя5,4 | — | 0,6 % | 9 дек. 2024 г. |
35Наблюдать | CVE-2022-47181Эксплойта нет | WordPress Email Templates Plugin <= 1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)wpexperts · email templates customizer and designer · CWE-352 | Высокая8,8 | — | 0,3 % | 7 нояб. 2023 г. |
21Наблюдать | CVE-2022-45821Эксплойта нет | WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)nootheme · noo timetable · CWE-79 | Средняя5,4 | — | 0,4 % | 8 авг. 2023 г. |
19Наблюдать | CVE-2022-47421Эксплойта нет | WordPress ARMember (free) and ARMember (premium) plugins - vulnerable to Auth. Stored Cross Site Scripting (XSS)armemberplugin · armember · CWE-79 | Средняя4,8 | — | 0,4 % | 18 июл. 2023 г. |
35Наблюдать | CVE-2022-46857Эксплойта нет | WordPress SiteAlert (Formerly WP Health) Plugin <= 1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)sitealert · sitealert · CWE-352 | Высокая8,8 | — | 0,3 % | 18 июл. 2023 г. |
35Наблюдать | CVE-2022-45828Эксплойта нет | WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Request Forgery (CSRF)nootheme · noo timetable · CWE-352 | Высокая8,8 | — | 0,3 % | 18 июл. 2023 г. |
35Наблюдать | CVE-2022-45823Эксплойта нет | WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Request Forgery (CSRF)video contest wordpress project · video contest wordpress · CWE-352 | Высокая8,8 | — | 0,3 % | 11 июл. 2023 г. |
19Наблюдать | CVE-2022-45827Эксплойта нет | WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)galleryplugins · video contest · CWE-79 | Средняя4,8 | — | 0,4 % | 12 июн. 2023 г. |
35Наблюдать | CVE-2022-47144Эксплойта нет | WordPress Mediamatic – Media Library Folders Plugin <= 2.8.1 is vulnerable to Cross Site Request Forgery (CSRF)frenify · mediamatic · CWE-352 | Высокая8,8 | — | 0,2 % | 25 мая 2023 г. |
35Наблюдать | CVE-2022-46856Эксплойта нет | WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF)orion · woocommerce products designer · CWE-352 | Высокая8,8 | — | 0,3 % | 25 мая 2023 г. |
35Наблюдать | CVE-2022-46810Эксплойта нет | WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF)villatheme · woocommerce thank you page customizer · CWE-352 | Высокая8,8 | — | 0,2 % | 25 мая 2023 г. |
35Наблюдать | CVE-2022-47177Эксплойта нет | WordPress WP EasyPay Plugin <= 4.1 is vulnerable to Cross Site Request Forgery (CSRF)wpeasypay · wp easypay · CWE-352 | Высокая8,8 | — | 0,3 % | 25 мая 2023 г. |
- CVE-2022-4760121Наблюдать
WordPress WP Table Manager plugin <= 3.5.2 - Broken Access Control
СредняяCVSS 5,3Эксплойта нетEPSS 0 %joomunited · wp table manager2 янв. 2025 г.
- CVE-2023-3999417Наблюдать
WordPress ARMember Premium plugin <= 5.9.2 - Broken Access Control
СредняяCVSS 4,3Эксплойта нетEPSS 0 %reputeinfosystems · armember2 янв. 2025 г.
- CVE-2023-3999621Наблюдать
WordPress Accordion and Accordion Slider plugin <= 1.2.4 - Broken Access Control
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wp onlinesupport, essential plugin · accordion and accordion slider13 дек. 2024 г.
- CVE-2023-3999517Наблюдать
WordPress Portfolio and Projects plugin <= 1.3.7 - Broken Access Control vulnerability
СредняяCVSS 4,3Эксплойта нетEPSS 0 %wp onlinesupport, essential plugin · portfolio and projects13 дек. 2024 г.
- CVE-2023-3651921Наблюдать
WordPress SW Product Bundles plugin <= 2.0.15 - Broken Access Control vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpthemego · sw product bundles13 дек. 2024 г.
- CVE-2023-3651817Наблюдать
WordPress Post Hit Counter plugin <= 1.3.2 - Broken Access Control
СредняяCVSS 4,3Эксплойта нетEPSS 0 %hugh lashbrooke · post hit counter13 дек. 2024 г.
- CVE-2022-4718221Наблюдать
WordPress APIExperts Square for WooCommerce plugin <= 4.4.1 - Broken Access Control
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wpexpertsio · apiexperts square for woocommerce13 дек. 2024 г.
- CVE-2022-4684621Наблюдать
WordPress Trending/Popular Post Slider and Widget plugin <= 1.5.7 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wp onlinesupport, essential plugin · trending/popular post slider and widget13 дек. 2024 г.
- CVE-2022-4681117Наблюдать
WordPress ALD Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 1.0.21 - Broken Access Control + CSRF
СредняяCVSS 4,3Эксплойта нетEPSS 1 %villatheme(villatheme.com) · ald – dropshipping and fulfillment for aliexpress and woocommerce13 дек. 2024 г.
- CVE-2022-4680717Наблюдать
WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Control
СредняяCVSS 4,3Эксплойта нетEPSS 1 %lauri karisola / wp trio · stock sync for woocommerce13 дек. 2024 г.
- CVE-2023-3048821Наблюдать
WordPress Featured Post Creative plugin <= 1.2.7 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %wp onlinesupport, essential plugin · featured post creative9 дек. 2024 г.
- CVE-2023-2570321Наблюдать
WordPress Meta slider and carousel with lightbox plugin <= 1.6.2 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wp onlinesupport, essential plugin · meta slider and carousel with lightbox9 дек. 2024 г.
- CVE-2023-2506021Наблюдать
WordPress Album and Image Gallery plus Lightbox plugin <= 1.6.2 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wp onlinesupport, essential plugin · album and image gallery plus lightbox9 дек. 2024 г.
- CVE-2023-2386821Наблюдать
WordPress Cost of Goods for WooCommerce plugin <= 2.8.6 - Broken Access Control vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpfactory · cost of goods for woocommerce9 дек. 2024 г.
- CVE-2022-4718135Наблюдать
WordPress Email Templates Plugin <= 1.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpexperts · email templates customizer and designer7 нояб. 2023 г.
- CVE-2022-4582121Наблюдать
WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 5,4Эксплойта нетEPSS 0 %nootheme · noo timetable8 авг. 2023 г.
- CVE-2022-4742119Наблюдать
WordPress ARMember (free) and ARMember (premium) plugins - vulnerable to Auth. Stored Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %armemberplugin · armember18 июл. 2023 г.
- CVE-2022-4685735Наблюдать
WordPress SiteAlert (Formerly WP Health) Plugin <= 1.9.7 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sitealert · sitealert18 июл. 2023 г.
- CVE-2022-4582835Наблюдать
WordPress NOO Timetable Plugin <= 2.1.3 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %nootheme · noo timetable18 июл. 2023 г.
- CVE-2022-4582335Наблюдать
WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %video contest wordpress project · video contest wordpress11 июл. 2023 г.
- CVE-2022-4582719Наблюдать
WordPress Video Contest WordPress Plugin Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %galleryplugins · video contest12 июн. 2023 г.
- CVE-2022-4714435Наблюдать
WordPress Mediamatic – Media Library Folders Plugin <= 2.8.1 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %frenify · mediamatic25 мая 2023 г.
- CVE-2022-4685635Наблюдать
WordPress Woocommerce Product Designer Plugin <= 4.3.3 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %orion · woocommerce products designer25 мая 2023 г.
- CVE-2022-4681035Наблюдать
WordPress Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %villatheme · woocommerce thank you page customizer25 мая 2023 г.
- CVE-2022-4717735Наблюдать
WordPress WP EasyPay Plugin <= 4.1 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpeasypay · wp easypay25 мая 2023 г.