dc11
50 записей с упоминанием · 1 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
29Наблюдать | CVE-2026-13690Эксплойта нет | UsersWP < 1.2.67 - Two-Factor Authentication Bypassunknown · userswp · CWE-287 | Высокая7,4 | — | 0,4 % | 29 июл. 2026 г. |
24Наблюдать | CVE-2023-0479Эксплойта нет | Print Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSStychesoftwares · print invoice \& delivery notes for woocommerce · CWE-79 | Средняя6,1 | — | 0,5 % | 16 янв. 2024 г. |
40В плане | CVE-2023-0224Эксплойта нет | GiveWP < 2.24.1 - Unauthenticated SQLigivewp · givewp · CWE-89 | Критическая9,8 | — | 3,7 % | 16 янв. 2024 г. |
21Наблюдать | CVE-2021-24559Эксплойта нет | Qyrr < 0.7 - Authenticated (contributor+) Stored XSSpatrickposner · qyrr · CWE-79 | Средняя5,4 | — | 0,2 % | 16 янв. 2024 г. |
24Наблюдать | CVE-2021-24432Эксплойта нет | Advanced AJAX Product Filters < 1.5.4.7 - Unauthenticated Reflected Cross-Site Scripting (XSS)berocket · advanced ajax product filters · CWE-79 | Средняя6,1 | — | 0,4 % | 16 янв. 2024 г. |
38Наблюдать | CVE-2023-5674Эксплойта нет | WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs/send_mail endpointwpvibes · wp mail log · CWE-89 | Высокая8,8 | — | 10,8 % | 26 дек. 2023 г. |
35Наблюдать | CVE-2023-5673Эксплойта нет | WP Mail Log < 1.1.3 – Contributor+ Arbitrary File Upload to RCEwpvibes · wp mail log · CWE-434 | Высокая8,8 | — | 1,1 % | 26 дек. 2023 г. |
26Наблюдать | CVE-2023-5672Эксплойта нет | WP Mail Log < 1.1.3 – Contributor+ LFI in wml_logs/send_mail endpointwpvibes · wp mail log · CWE-22 | Средняя6,5 | — | 0,7 % | 26 дек. 2023 г. |
35Наблюдать | CVE-2023-5645Эксплойта нет | WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpointwpvibes · wp mail log · CWE-89 | Высокая8,8 | — | 0,7 % | 26 дек. 2023 г. |
30Наблюдать | CVE-2023-5644Эксплойта нет | WP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpointswpvibes · wp mail log · CWE-863 | Высокая7,6 | — | 0,5 % | 26 дек. 2023 г. |
24Наблюдать | CVE-2023-5325Эксплойта нет | Woocommerce Vietnam Checkout < 2.0.6 - Unauthenticated Stored XSSlevantoan · woocommerce vietnam checkout · CWE-79 | Средняя6,1 | — | 0,5 % | 27 нояб. 2023 г. |
21Наблюдать | CVE-2023-4823Эксплойта нет | WP Meta and Date Remover < 2.2.0 - Subscriber+ Stored XSSprasadkirpekar · wp meta and date remover · CWE-79 | Средняя5,4 | — | 0,4 % | 31 окт. 2023 г. |
40В плане | CVE-2023-4666Proof of concept | Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload10web · form maker · CWE-434 | Критическая9,8 | — | 3,3 % | 16 окт. 2023 г. |
28Наблюдать | CVE-2023-2805Эксплойта нет | SupportCandy < 3.1.7 - Admin+ SQLisupportcandy · supportcandy · CWE-89 | Высокая7,2 | — | 0,9 % | 19 июн. 2023 г. |
35Наблюдать | CVE-2023-2719Эксплойта нет | SupportCandy < 3.1.7 - Subscriber+ SQLisupportcandy · supportcandy · CWE-89 | Высокая8,8 | — | 1,2 % | 19 июн. 2023 г. |
51В плане | CVE-2023-1730Proof of concept | SupportCandy < 3.1.5 - Unauthenticated SQLisupportcandy · supportcandy · CWE-89 | Критическая9,8 | — | 40,6 % | 2 мая 2023 г. |
26Наблюдать | CVE-2023-0889Эксплойта нет | TF Random Numbers < 2.0.1 - Subscriber+ Arbitrary Option Updatemetagauss · themeflection numbers · CWE-862 | Средняя6,5 | — | 0,3 % | 17 апр. 2023 г. |
35Наблюдать | CVE-2023-0765Эксплойта нет | Gallery by BestWebSoft < 4.7.0 - Author+ SQL Injectionbestwebsoft · gallery · CWE-89 | Высокая8,8 | — | 0,9 % | 17 апр. 2023 г. |
21Наблюдать | CVE-2023-0764Эксплойта нет | Gallery by BestWebSoft < 4.7.0 - Author+ Stored Cross-Site Scriptingbestwebsoft · gallery · CWE-79 | Средняя5,4 | — | 0,4 % | 17 апр. 2023 г. |
35Наблюдать | CVE-2023-0820Эксплойта нет | User Role by BestWebSoft < 1.6.7 - Privilege Escalation via CSRFbestwebsoft · user role · CWE-352 | Высокая8,8 | — | 0,4 % | 3 апр. 2023 г. |
32Наблюдать | CVE-2023-0441Эксплойта нет | Gallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options Updatesimplygallery · simply gallery blocks with lightbox · CWE-862 | Высокая8,1 | — | 0,7 % | 27 мар. 2023 г. |
35Наблюдать | CVE-2023-0940Эксплойта нет | ProfileGrid < 5.3.1 - Subscriber+ Arbitrary Password Resetmetagauss · profilegrid · CWE-863 | Высокая8,8 | — | 0,8 % | 20 мар. 2023 г. |
24Наблюдать | CVE-2023-0876Proof of concept | WP Meta SEO < 4.5.3 - Subscriber+ Improper Authorization causing Arbitrary Redirectjoomunited · wp meta seo · CWE-601 | Средняя6,1 | — | 0,7 % | 20 мар. 2023 г. |
35Наблюдать | CVE-2023-0875Эксплойта нет | WP Meta SEO < 4.5.3 - Subscriber+ SQLijoomunited · wp meta seo · CWE-89 | Высокая8,8 | — | 0,9 % | 20 мар. 2023 г. |
35Наблюдать | CVE-2023-0477Эксплойта нет | Auto Featured Image < 3.9.16 - Author+ Arbitrary File Uploadcm-wp · auto featured image · CWE-434 | Высокая8,8 | — | 1,6 % | 13 мар. 2023 г. |
- CVE-2026-1369029Наблюдать
UsersWP < 1.2.67 - Two-Factor Authentication Bypass
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %unknown · userswp29 июл. 2026 г.
- CVE-2023-047924Наблюдать
Print Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS
СредняяCVSS 6,1Эксплойта нетEPSS 1 %tychesoftwares · print invoice \& delivery notes for woocommerce16 янв. 2024 г.
- CVE-2023-022440В плане
GiveWP < 2.24.1 - Unauthenticated SQLi
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %givewp · givewp16 янв. 2024 г.
- CVE-2021-2455921Наблюдать
Qyrr < 0.7 - Authenticated (contributor+) Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 0 %patrickposner · qyrr16 янв. 2024 г.
- CVE-2021-2443224Наблюдать
Advanced AJAX Product Filters < 1.5.4.7 - Unauthenticated Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %berocket · advanced ajax product filters16 янв. 2024 г.
- CVE-2023-567438Наблюдать
WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs/send_mail endpoint
ВысокаяCVSS 8,8Эксплойта нетEPSS 11 %wpvibes · wp mail log26 дек. 2023 г.
- CVE-2023-567335Наблюдать
WP Mail Log < 1.1.3 – Contributor+ Arbitrary File Upload to RCE
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpvibes · wp mail log26 дек. 2023 г.
- CVE-2023-567226Наблюдать
WP Mail Log < 1.1.3 – Contributor+ LFI in wml_logs/send_mail endpoint
СредняяCVSS 6,5Эксплойта нетEPSS 1 %wpvibes · wp mail log26 дек. 2023 г.
- CVE-2023-564535Наблюдать
WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpoint
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpvibes · wp mail log26 дек. 2023 г.
- CVE-2023-564430Наблюдать
WP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpoints
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %wpvibes · wp mail log26 дек. 2023 г.
- CVE-2023-532524Наблюдать
Woocommerce Vietnam Checkout < 2.0.6 - Unauthenticated Stored XSS
СредняяCVSS 6,1Эксплойта нетEPSS 0 %levantoan · woocommerce vietnam checkout27 нояб. 2023 г.
- CVE-2023-482321Наблюдать
WP Meta and Date Remover < 2.2.0 - Subscriber+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 0 %prasadkirpekar · wp meta and date remover31 окт. 2023 г.
- CVE-2023-466640В плане
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Proof of conceptEPSS 3 %10web · form maker16 окт. 2023 г.
- CVE-2023-280528Наблюдать
SupportCandy < 3.1.7 - Admin+ SQLi
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %supportcandy · supportcandy19 июн. 2023 г.
- CVE-2023-271935Наблюдать
SupportCandy < 3.1.7 - Subscriber+ SQLi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %supportcandy · supportcandy19 июн. 2023 г.
- CVE-2023-173051В плане
SupportCandy < 3.1.5 - Unauthenticated SQLi
КритическаяCVSS 9,8Proof of conceptEPSS 41 %supportcandy · supportcandy2 мая 2023 г.
- CVE-2023-088926Наблюдать
TF Random Numbers < 2.0.1 - Subscriber+ Arbitrary Option Update
СредняяCVSS 6,5Эксплойта нетEPSS 0 %metagauss · themeflection numbers17 апр. 2023 г.
- CVE-2023-076535Наблюдать
Gallery by BestWebSoft < 4.7.0 - Author+ SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bestwebsoft · gallery17 апр. 2023 г.
- CVE-2023-076421Наблюдать
Gallery by BestWebSoft < 4.7.0 - Author+ Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bestwebsoft · gallery17 апр. 2023 г.
- CVE-2023-082035Наблюдать
User Role by BestWebSoft < 1.6.7 - Privilege Escalation via CSRF
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bestwebsoft · user role3 апр. 2023 г.
- CVE-2023-044132Наблюдать
Gallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options Update
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %simplygallery · simply gallery blocks with lightbox27 мар. 2023 г.
- CVE-2023-094035Наблюдать
ProfileGrid < 5.3.1 - Subscriber+ Arbitrary Password Reset
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %metagauss · profilegrid20 мар. 2023 г.
- CVE-2023-087624Наблюдать
WP Meta SEO < 4.5.3 - Subscriber+ Improper Authorization causing Arbitrary Redirect
СредняяCVSS 6,1Proof of conceptEPSS 1 %joomunited · wp meta seo20 мар. 2023 г.
- CVE-2023-087535Наблюдать
WP Meta SEO < 4.5.3 - Subscriber+ SQLi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %joomunited · wp meta seo20 мар. 2023 г.
- CVE-2023-047735Наблюдать
Auto Featured Image < 3.9.16 - Author+ Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %cm-wp · auto featured image13 мар. 2023 г.