ifoundbug
16 записей с упоминанием · 12 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2026-2144Эксплойта нет | Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storagekatsushi-kawamori · magic login mail or qr code · CWE-269 | Высокая8,1 | — | 0,5 % | 14 февр. 2026 г. |
18Наблюдать | CVE-2025-12540Эксплойта нет | ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposuresharethis · sharethis dashboard for google analytics · CWE-200 | Средняя4,7 | — | 0,3 % | 7 янв. 2026 г. |
39Наблюдать | CVE-2025-10738Эксплойта нет | URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injectionrupok98 · url shortener plugin for wordpress · CWE-89 | Критическая9,8 | — | 0,4 % | 13 дек. 2025 г. |
39Наблюдать | CVE-2025-11456Эксплойта нет | ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Uploadelula · wsdesk · CWE-434 | Критическая9,8 | — | 0,7 % | 21 нояб. 2025 г. |
31Наблюдать | CVE-2025-12139Proof of concept | File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposureprinceahmed · file manager for google drive – integrate google drive · CWE-200 | Высокая7,5 | — | 2,3 % | 5 нояб. 2025 г. |
28Наблюдать | CVE-2025-11995Эксплойта нет | Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scriptingjackdewey · community events · CWE-79 | Высокая7,2 | — | 0,3 % | 1 нояб. 2025 г. |
25Наблюдать | CVE-2025-10740Эксплойта нет | URL Shortener Plugin For WordPress <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Link Manipulationrupok98 · url shortener plugin for wordpress · CWE-89 | Средняя6,3 | — | 0,3 % | 24 окт. 2025 г. |
28Наблюдать | CVE-2025-10754Эксплойта нет | DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Uploadgeolocationtechnology · docodoco store locator · CWE-434 | Высокая7,2 | — | 0,7 % | 15 окт. 2025 г. |
28Наблюдать | CVE-2025-10313Эксплойта нет | Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scriptingjankimoradiya · find and replace content for wordpress · CWE-862 | Высокая7,2 | — | 0,3 % | 15 окт. 2025 г. |
39Наблюдать | CVE-2025-10586Эксплойта нет | Community Events <= 1.5.1 - Unauthenticated SQL Injectionjackdewey · community events · CWE-89 | Критическая9,8 | — | 0,5 % | 8 окт. 2025 г. |
28Наблюдать | CVE-2025-11204Эксплойта нет | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injectionmetagauss · registrationmagic – custom registration forms, user registration, payment, and user login · CWE-89 | Высокая7,2 | — | 0,4 % | 8 окт. 2025 г. |
39Наблюдать | CVE-2025-10587Эксплойта нет | Community Events <= 1.5.1 - Unauthenticated SQL Injectionjackdewey · community events · CWE-89 | Критическая9,8 | — | 0,4 % | 8 окт. 2025 г. |
25Наблюдать | CVE-2025-9985Proof of concept | Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log Filemarceljm · featured image from url (fifu) · CWE-532 | Средняя5,3 | — | 11,8 % | 26 сент. 2025 г. |
21Наблюдать | CVE-2025-9984Эксплойта нет | Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosuremarceljm · featured image from url (fifu) · CWE-862 | Средняя5,3 | — | 0,3 % | 26 сент. 2025 г. |
19Наблюдать | CVE-2025-10037Эксплойта нет | Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injectionmarceljm · featured image from url (fifu) · CWE-89 | Средняя4,9 | — | 0,3 % | 26 сент. 2025 г. |
19Наблюдать | CVE-2025-10036Эксплойта нет | Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injectionmarceljm · featured image from url (fifu) · CWE-89 | Средняя4,9 | — | 0,3 % | 26 сент. 2025 г. |
- CVE-2026-214432Наблюдать
Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %katsushi-kawamori · magic login mail or qr code14 февр. 2026 г.
- CVE-2025-1254018Наблюдать
ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposure
СредняяCVSS 4,7Эксплойта нетEPSS 0 %sharethis · sharethis dashboard for google analytics7 янв. 2026 г.
- CVE-2025-1073839Наблюдать
URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %rupok98 · url shortener plugin for wordpress13 дек. 2025 г.
- CVE-2025-1145639Наблюдать
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %elula · wsdesk21 нояб. 2025 г.
- CVE-2025-1213931Наблюдать
File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %princeahmed · file manager for google drive – integrate google drive5 нояб. 2025 г.
- CVE-2025-1199528Наблюдать
Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %jackdewey · community events1 нояб. 2025 г.
- CVE-2025-1074025Наблюдать
URL Shortener Plugin For WordPress <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Link Manipulation
СредняяCVSS 6,3Эксплойта нетEPSS 0 %rupok98 · url shortener plugin for wordpress24 окт. 2025 г.
- CVE-2025-1075428Наблюдать
DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Upload
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %geolocationtechnology · docodoco store locator15 окт. 2025 г.
- CVE-2025-1031328Наблюдать
Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %jankimoradiya · find and replace content for wordpress15 окт. 2025 г.
- CVE-2025-1058639Наблюдать
Community Events <= 1.5.1 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jackdewey · community events8 окт. 2025 г.
- CVE-2025-1120428Наблюдать
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %metagauss · registrationmagic – custom registration forms, user registration, payment, and user login8 окт. 2025 г.
- CVE-2025-1058739Наблюдать
Community Events <= 1.5.1 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %jackdewey · community events8 окт. 2025 г.
- CVE-2025-998525Наблюдать
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
СредняяCVSS 5,3Proof of conceptEPSS 12 %marceljm · featured image from url (fifu)26 сент. 2025 г.
- CVE-2025-998421Наблюдать
Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %marceljm · featured image from url (fifu)26 сент. 2025 г.
- CVE-2025-1003719Наблюдать
Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection
СредняяCVSS 4,9Эксплойта нетEPSS 0 %marceljm · featured image from url (fifu)26 сент. 2025 г.
- CVE-2025-1003619Наблюдать
Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection
СредняяCVSS 4,9Эксплойта нетEPSS 0 %marceljm · featured image from url (fifu)26 сент. 2025 г.