Записи bitapps
26 опубликованных записей вендора bitapps.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 19,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-434 Unrestricted Upload of File with Dangerous Type6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-23 Relative Path Traversal2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-4774Эксплойта нет | Bit Form < 1.9 - RCE via Unauthenticated Arbitrary File Uploadbitapps · bit form · CWE-434 | Критическая9,8 | — | 1,8 % | 15 мая 2023 г. |
36Наблюдать | CVE-2024-7777Эксплойта нет | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrabitapps · contact form builder · CWE-22 | Критическая9,0 | — | 1,0 % | 20 авг. 2024 г. |
36Наблюдать | CVE-2024-43248Эксплойта нет | WordPress Bit Form Pro plugin <= 2.6.4 - Unauthenticated Arbitrary File Deletion vulnerabilitybitapps · bit form · CWE-22 | Критическая9,1 | — | 0,6 % | 19 авг. 2024 г. |
35Наблюдать | CVE-2024-7770Эксплойта нет | Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Uploadbitapps · file manager · CWE-434 | Высокая8,8 | — | 1,1 % | 10 сент. 2024 г. |
35Наблюдать | CVE-2024-43249Эксплойта нет | WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Arbitrary File Upload vulnerabilitybitapps · bit form · CWE-434 | Высокая8,8 | — | 1,0 % | 19 авг. 2024 г. |
33Наблюдать | CVE-2024-7627Proof of concept | Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Conditionbitapps · file manager · CWE-94 | Высокая8,1 | — | 2,8 % | 4 сент. 2024 г. |
32Наблюдать | CVE-2024-47319Эксплойта нет | WordPress Bit Form plugin <= 2.13.10 - Arbitrary File Upload vulnerabilitybit apps · bit form · CWE-434 | Высокая8,0 | — | 0,4 % | 5 окт. 2024 г. |
30Наблюдать | CVE-2024-13451Эксплойта нет | Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposurebitapps · bit form · CWE-200 | Высокая7,5 | — | 0,4 % | 2 июл. 2025 г. |
28Наблюдать | CVE-2024-6123Эксплойта нет | Bit Form <= 2.13.3 - Authenticated (Administrator+) Arbitrary File Uploadbitpressadmin · bit form – custom contact form, multi step, conversational form & payment form builder · CWE-434 | Высокая7,2 | — | 1,0 % | 9 июл. 2024 г. |
28Наблюдать | CVE-2022-47599Эксплойта нет | WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injectionbitapps · file manager · CWE-502 | Высокая7,2 | — | 0,5 % | 20 дек. 2023 г. |
28Наблюдать | CVE-2024-7780Эксплойта нет | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrabitapps · contact form builder · CWE-89 | Высокая7,2 | — | 0,5 % | 20 авг. 2024 г. |
28Наблюдать | CVE-2024-7702Эксплойта нет | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrabitapps · contact form builder · CWE-89 | Высокая7,2 | — | 0,5 % | 20 авг. 2024 г. |
27Наблюдать | CVE-2024-8743Proof of concept | Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Uploadbitpressadmin · file manager · CWE-434 | Средняя6,8 | — | 0,8 % | 5 окт. 2024 г. |
26Наблюдать | CVE-2024-7782Эксплойта нет | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrabitapps · contact form builder · CWE-22 | Средняя6,5 | — | 0,9 % | 20 авг. 2024 г. |
26Наблюдать | CVE-2023-5907Эксплойта нет | File Manager < 6.3 - Admin+ Arbitrary OS File/Folder Access + Path Traversalbitapps · file manager · CWE-552 | Средняя6,5 | — | 0,9 % | 11 дек. 2023 г. |
26Наблюдать | CVE-2025-0822Эксплойта нет | Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameterbitapps · bit assist · CWE-23 | Средняя6,5 | — | 0,6 % | 15 февр. 2025 г. |
26Наблюдать | CVE-2025-0821Эксплойта нет | Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameterbitapps · bit assist · CWE-89 | Средняя6,5 | — | 0,6 % | 14 февр. 2025 г. |
26Наблюдать | CVE-2024-43251Эксплойта нет | WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Sensitive Data Exposure vulnerabilitybitapps · bit form · CWE-200 | Средняя6,5 | — | 0,4 % | 26 авг. 2024 г. |
26Наблюдать | CVE-2024-13450Эксплойта нет | Contact Form by Bit Form <= 2.17.4 - Authenticated (Administrator+) Server-Side Request Forgerybitapps · contact form builder · CWE-918 | Средняя6,5 | — | 0,4 % | 25 янв. 2025 г. |
26Наблюдать | CVE-2024-43250Эксплойта нет | WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Plugin Settings Change vulnerabilitybitapps · bit form · CWE-863 | Средняя6,5 | — | 0,3 % | 19 авг. 2024 г. |
21Наблюдать | CVE-2024-1640Эксплойта нет | Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Rebitapps · contact form builder · CWE-639 | Средняя5,3 | — | 0,5 % | 13 мар. 2024 г. |
19Наблюдать | CVE-2024-13791Эксплойта нет | Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Functionbitapps · bit assist · CWE-23 | Средняя4,9 | — | 0,7 % | 14 февр. 2025 г. |
19Наблюдать | CVE-2023-3645Эксплойта нет | Contact Form Builder by Bit Form < 2.2.0 - Admin+ Stored XSSbitapps · contact form builder · CWE-79 | Средняя4,8 | — | 0,4 % | 14 авг. 2023 г. |
19Наблюдать | CVE-2023-3667Эксплойта нет | Bit Assist < 1.1.9 - Admin+ Stored Cross-Site Scriptingbitapps · bit assist · CWE-79 | Средняя4,8 | — | 0,4 % | 21 авг. 2023 г. |
19Наблюдать | CVE-2023-51371Эксплойта нет | WordPress Bit Assist Plugin <= 1.1.9 is vulnerable to Cross Site Scripting (XSS)bitapps · bit assist · CWE-79 | Средняя4,8 | — | 0,3 % | 29 дек. 2023 г. |
- CVE-2022-477440В плане
Bit Form < 1.9 - RCE via Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bitapps · bit form15 мая 2023 г.
- CVE-2024-777736Наблюдать
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administra
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %bitapps · contact form builder20 авг. 2024 г.
- CVE-2024-4324836Наблюдать
WordPress Bit Form Pro plugin <= 2.6.4 - Unauthenticated Arbitrary File Deletion vulnerability
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %bitapps · bit form19 авг. 2024 г.
- CVE-2024-777035Наблюдать
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.5 - Authenticated (Subscriber+) Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bitapps · file manager10 сент. 2024 г.
- CVE-2024-4324935Наблюдать
WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Arbitrary File Upload vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bitapps · bit form19 авг. 2024 г.
- CVE-2024-762733Наблюдать
Bit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition
ВысокаяCVSS 8,1Proof of conceptEPSS 3 %bitapps · file manager4 сент. 2024 г.
- CVE-2024-4731932Наблюдать
WordPress Bit Form plugin <= 2.13.10 - Arbitrary File Upload vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %bit apps · bit form5 окт. 2024 г.
- CVE-2024-1345130Наблюдать
Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %bitapps · bit form2 июл. 2025 г.
- CVE-2024-612328Наблюдать
Bit Form <= 2.13.3 - Authenticated (Administrator+) Arbitrary File Upload
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bitpressadmin · bit form – custom contact form, multi step, conversational form & payment form builder9 июл. 2024 г.
- CVE-2022-4759928Наблюдать
WordPress File Manager Plugin <= 5.2.7 is vulnerable to PHP Object Injection
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bitapps · file manager20 дек. 2023 г.
- CVE-2024-778028Наблюдать
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administra
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bitapps · contact form builder20 авг. 2024 г.
- CVE-2024-770228Наблюдать
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administra
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %bitapps · contact form builder20 авг. 2024 г.
- CVE-2024-874327Наблюдать
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited JavaScript File Upload
СредняяCVSS 6,8Proof of conceptEPSS 1 %bitpressadmin · file manager5 окт. 2024 г.
- CVE-2024-778226Наблюдать
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administra
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bitapps · contact form builder20 авг. 2024 г.
- CVE-2023-590726Наблюдать
File Manager < 6.3 - Admin+ Arbitrary OS File/Folder Access + Path Traversal
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bitapps · file manager11 дек. 2023 г.
- CVE-2025-082226Наблюдать
Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bitapps · bit assist15 февр. 2025 г.
- CVE-2025-082126Наблюдать
Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameter
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bitapps · bit assist14 февр. 2025 г.
- CVE-2024-4325126Наблюдать
WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Sensitive Data Exposure vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 0 %bitapps · bit form26 авг. 2024 г.
- CVE-2024-1345026Наблюдать
Contact Form by Bit Form <= 2.17.4 - Authenticated (Administrator+) Server-Side Request Forgery
СредняяCVSS 6,5Эксплойта нетEPSS 0 %bitapps · contact form builder25 янв. 2025 г.
- CVE-2024-4325026Наблюдать
WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Plugin Settings Change vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 0 %bitapps · bit form19 авг. 2024 г.
- CVE-2024-164021Наблюдать
Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Re
СредняяCVSS 5,3Эксплойта нетEPSS 0 %bitapps · contact form builder13 мар. 2024 г.
- CVE-2024-1379119Наблюдать
Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function
СредняяCVSS 4,9Эксплойта нетEPSS 1 %bitapps · bit assist14 февр. 2025 г.
- CVE-2023-364519Наблюдать
Contact Form Builder by Bit Form < 2.2.0 - Admin+ Stored XSS
СредняяCVSS 4,8Эксплойта нетEPSS 0 %bitapps · contact form builder14 авг. 2023 г.
- CVE-2023-366719Наблюдать
Bit Assist < 1.1.9 - Admin+ Stored Cross-Site Scripting
СредняяCVSS 4,8Эксплойта нетEPSS 0 %bitapps · bit assist21 авг. 2023 г.
- CVE-2023-5137119Наблюдать
WordPress Bit Assist Plugin <= 1.1.9 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %bitapps · bit assist29 дек. 2023 г.