Записи bbPress
6 опубликованных записей вендора bbpress.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 16,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2020-13693Proof of concept | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.bbpress · bbpress | Критическая9,8 | — | 43,9 % | 28 мая 2020 г. |
31Наблюдать | CVE-2007-3244Эксплойта нет | SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrarbbpress · bbpress | Высокая7,5 | — | 1,8 % | 14 июн. 2007 г. |
24Наблюдать | CVE-2011-1150Эксплойта нет | bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.bbpress · bbpress · CWE-79 | Средняя6,1 | — | 0,9 % | 5 февр. 2020 г. |
20Наблюдать | CVE-2011-3710Эксплойта нет | bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pabbpress · bbpress · CWE-200 | Средняя5,0 | — | 1,6 % | 23 сент. 2011 г. |
19Наблюдать | CVE-2020-13487Эксплойта нет | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/ebbpress · bbpress · CWE-79 | Средняя4,8 | — | 1,6 % | 26 мая 2020 г. |
18Наблюдать | CVE-2007-3243Proof of concept | Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML viabbpress · bbpress | Средняя4,3 | — | 1,8 % | 14 июн. 2007 г. |
- CVE-2020-1369352В плане
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
КритическаяCVSS 9,8Proof of conceptEPSS 44 %bbpress · bbpress28 мая 2020 г.
- CVE-2007-324431Наблюдать
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrar
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bbpress · bbpress14 июн. 2007 г.
- CVE-2011-115024Наблюдать
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bbpress · bbpress5 февр. 2020 г.
- CVE-2011-371020Наблюдать
bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa
СредняяCVSS 5,0Эксплойта нетEPSS 2 %bbpress · bbpress23 сент. 2011 г.
- CVE-2020-1348719Наблюдать
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/e
СредняяCVSS 4,8Эксплойта нетEPSS 2 %bbpress · bbpress26 мая 2020 г.
- CVE-2007-324318Наблюдать
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Proof of conceptEPSS 2 %bbpress · bbpress14 июн. 2007 г.