Deadbee
16 записей с упоминанием · 16 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
17Наблюдать | CVE-2026-5582Эксплойта нет | FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Togglefusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.) · CWE-352 | Средняя4,3 | — | 0,2 % | 30 июл. 2026 г. |
25Наблюдать | CVE-2026-0736Эксплойта нет | Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Fieldcollectchat · chatbot for wordpress by collect.chat ⚡️ · CWE-79 | Средняя6,4 | — | 0,3 % | 14 февр. 2026 г. |
28Наблюдать | CVE-2026-1320Эксплойта нет | Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Headerays-pro · secure copy content protection and content locking · CWE-79 | Высокая7,2 | — | 0,3 % | 12 февр. 2026 г. |
21Наблюдать | CVE-2025-15510Эксплойта нет | NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposurewebaways · nex-forms – ultimate forms plugin for wordpress · CWE-862 | Средняя5,3 | — | 0,3 % | 30 янв. 2026 г. |
29Наблюдать | CVE-2026-0832Эксплойта нет | New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosuresaadiqbal · new user approve · CWE-862 | Высокая7,3 | — | 0,4 % | 28 янв. 2026 г. |
24Наблюдать | CVE-2025-14375Эксплойта нет | RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via classNamerebelcode · rss aggregator – rss import, news feeds, feed to post, and autoblogging · CWE-79 | Средняя6,1 | — | 0,2 % | 16 янв. 2026 г. |
21Наблюдать | CVE-2025-14507Эксплойта нет | EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST APImetagauss · eventprime – events calendar, bookings and tickets · CWE-200 | Средняя5,3 | — | 0,4 % | 13 янв. 2026 г. |
21Наблюдать | CVE-2025-14043Эксплойта нет | Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creationtainacan · tainacan · CWE-862 | Средняя5,3 | — | 0,3 % | 20 дек. 2025 г. |
17Наблюдать | CVE-2025-14277Эксплойта нет | Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgerybdthemes · prime slider – addons for elementor · CWE-918 | Средняя4,3 | — | 0,3 % | 18 дек. 2025 г. |
21Наблюдать | CVE-2025-14442Эксплойта нет | Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export Fileays-pro · secure copy content protection and content locking · CWE-552 | Средняя5,3 | — | 0,3 % | 12 дек. 2025 г. |
17Наблюдать | CVE-2025-14159Эксплойта нет | Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Exportays-pro · secure copy content protection and content locking · CWE-352 | Средняя4,3 | — | 0,2 % | 12 дек. 2025 г. |
21Наблюдать | CVE-2025-13006Эксплойта нет | SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposurewpeka-club · surveyfunnel – survey plugin for wordpress · CWE-200 | Средняя5,3 | — | 0,3 % | 5 дек. 2025 г. |
17Наблюдать | CVE-2025-13685Эксплойта нет | Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actionsays-pro · photo gallery by ays – responsive image gallery · CWE-352 | Средняя4,3 | — | 0,2 % | 2 дек. 2025 г. |
17Наблюдать | CVE-2025-13143Эксплойта нет | Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnectionassafp · quiz, poll & survey maker by opinion stage · CWE-352 | Средняя4,3 | — | 0,2 % | 27 нояб. 2025 г. |
21Наблюдать | CVE-2025-12747Эксплойта нет | Tainacan <= 1.0.0 - Unauthenticated Information Exposuretainacan · tainacan · CWE-552 | Средняя5,3 | — | 0,3 % | 21 нояб. 2025 г. |
24Наблюдать | CVE-2025-12746Эксплойта нет | Tainacan <= 1.0.0 - Reflected Cross-Site Scriptingtainacan · tainacan · CWE-79 | Средняя6,1 | — | 0,3 % | 21 нояб. 2025 г. |
- CVE-2026-558217Наблюдать
FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle
СредняяCVSS 4,3Эксплойта нетEPSS 0 %fusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.)30 июл. 2026 г.
- CVE-2026-073625Наблюдать
Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field
СредняяCVSS 6,4Эксплойта нетEPSS 0 %collectchat · chatbot for wordpress by collect.chat ⚡️14 февр. 2026 г.
- CVE-2026-132028Наблюдать
Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %ays-pro · secure copy content protection and content locking12 февр. 2026 г.
- CVE-2025-1551021Наблюдать
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %webaways · nex-forms – ultimate forms plugin for wordpress30 янв. 2026 г.
- CVE-2026-083229Наблюдать
New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %saadiqbal · new user approve28 янв. 2026 г.
- CVE-2025-1437524Наблюдать
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rebelcode · rss aggregator – rss import, news feeds, feed to post, and autoblogging16 янв. 2026 г.
- CVE-2025-1450721Наблюдать
EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API
СредняяCVSS 5,3Эксплойта нетEPSS 0 %metagauss · eventprime – events calendar, bookings and tickets13 янв. 2026 г.
- CVE-2025-1404321Наблюдать
Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation
СредняяCVSS 5,3Эксплойта нетEPSS 0 %tainacan · tainacan20 дек. 2025 г.
- CVE-2025-1427717Наблюдать
Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery
СредняяCVSS 4,3Эксплойта нетEPSS 0 %bdthemes · prime slider – addons for elementor18 дек. 2025 г.
- CVE-2025-1444221Наблюдать
Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ays-pro · secure copy content protection and content locking12 дек. 2025 г.
- CVE-2025-1415917Наблюдать
Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export
СредняяCVSS 4,3Эксплойта нетEPSS 0 %ays-pro · secure copy content protection and content locking12 дек. 2025 г.
- CVE-2025-1300621Наблюдать
SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %wpeka-club · surveyfunnel – survey plugin for wordpress5 дек. 2025 г.
- CVE-2025-1368517Наблюдать
Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions
СредняяCVSS 4,3Эксплойта нетEPSS 0 %ays-pro · photo gallery by ays – responsive image gallery2 дек. 2025 г.
- CVE-2025-1314317Наблюдать
Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection
СредняяCVSS 4,3Эксплойта нетEPSS 0 %assafp · quiz, poll & survey maker by opinion stage27 нояб. 2025 г.
- CVE-2025-1274721Наблюдать
Tainacan <= 1.0.0 - Unauthenticated Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %tainacan · tainacan21 нояб. 2025 г.
- CVE-2025-1274624Наблюдать
Tainacan <= 1.0.0 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %tainacan · tainacan21 нояб. 2025 г.