Записи bPlugins
22 опубликованных записей вендора bplugins.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 45,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2024-1061Proof of concept | The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' paramebplugins · html5 video player · CWE-89 | Критическая9,8 | — | 11,2 % | 30 янв. 2024 г. |
35Наблюдать | CVE-2023-46084Эксплойта нет | WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injectionbplugins · icons font loader · CWE-89 | Высокая8,8 | — | 0,5 % | 6 нояб. 2023 г. |
35Наблюдать | CVE-2024-43296Эксплойта нет | WordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerabilitybplugins · html5 video player · CWE-862 | Высокая8,8 | — | 0,4 % | 1 нояб. 2024 г. |
35Наблюдать | CVE-2025-22787Эксплойта нет | WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerabilitybplugins · button block · CWE-862 | Высокая8,8 | — | 0,3 % | 15 янв. 2025 г. |
28Наблюдать | CVE-2023-5860Эксплойта нет | Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Uploadbplugins · icons font loader · CWE-434 | Высокая7,2 | — | 1,0 % | 2 нояб. 2023 г. |
28Наблюдать | CVE-2024-24714Эксплойта нет | WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Uploadbplugins · icons font loader · CWE-434 | Высокая7,2 | — | 0,6 % | 26 февр. 2024 г. |
27Наблюдать | CVE-2024-5522Proof of concept | HTML5 Video Player < 2.5.27 - Unauthenticated SQLibplugins · html5 video player · CWE-89 | Средняя6,5 | — | 2,6 % | 20 июн. 2024 г. |
26Наблюдать | CVE-2024-10671Эксплойта нет | Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosurebplugins · button block · CWE-639 | Средняя6,5 | — | 0,5 % | 21 нояб. 2024 г. |
26Наблюдать | CVE-2024-12560Эксплойта нет | Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplicationbplugins · button block · CWE-200 | Средняя6,5 | — | 0,4 % | 19 дек. 2024 г. |
24Наблюдать | CVE-2024-23508Эксплойта нет | WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS)bplugins · pdf poster · CWE-79 | Средняя6,1 | — | 0,3 % | 31 янв. 2024 г. |
21Наблюдать | CVE-2021-24775Эксплойта нет | Document Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosurebplugins · document embedder · CWE-668 | Средняя5,3 | — | 1,3 % | 1 февр. 2022 г. |
21Наблюдать | CVE-2021-24412Эксплойта нет | Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scriptingbplugins · html5 audio player · CWE-79 | Средняя5,4 | — | 0,7 % | 18 окт. 2021 г. |
21Наблюдать | CVE-2021-24413Эксплойта нет | Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scriptingbplugins · easy twitter feed · CWE-79 | Средняя5,4 | — | 0,7 % | 18 окт. 2021 г. |
21Наблюдать | CVE-2021-24416Эксплойта нет | StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scriptingbplugins · streamcast radio player · CWE-79 | Средняя5,4 | — | 0,6 % | 18 окт. 2021 г. |
21Наблюдать | CVE-2021-24415Эксплойта нет | Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scriptingbplugins · polo video gallery · CWE-79 | Средняя5,4 | — | 0,6 % | 18 окт. 2021 г. |
21Наблюдать | CVE-2023-0170Эксплойта нет | Html5 Audio Player < 2.1.12 - Contributor+ Stored XSSbplugins · html5 audio player · CWE-79 | Средняя5,4 | — | 0,6 % | 6 февр. 2023 г. |
21Наблюдать | CVE-2023-6485Эксплойта нет | Html5 Video Player < 2.5.19 - Subscriber+ Stored XSSbplugins · html5 video player · CWE-79 | Средняя5,4 | — | 0,5 % | 1 янв. 2024 г. |
21Наблюдать | CVE-2024-7727Эксплойта нет | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handlerbplugins · html5 video player · CWE-862 | Средняя5,3 | — | 0,4 % | 11 сент. 2024 г. |
21Наблюдать | CVE-2024-37445Эксплойта нет | WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerabilitybplugins · html5 audio player · CWE-79 | Средняя5,4 | — | 0,3 % | 22 июл. 2024 г. |
21Наблюдать | CVE-2025-22815Эксплойта нет | WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerabilitybplugins · button block · CWE-79 | Средняя5,4 | — | 0,2 % | 9 янв. 2025 г. |
17Наблюдать | CVE-2021-24868Эксплойта нет | Document Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosurebplugins · document embedder · CWE-668 | Средняя4,3 | — | 0,9 % | 1 февр. 2022 г. |
17Наблюдать | CVE-2024-7721Эксплойта нет | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Updatebplugins · html5 video player · CWE-862 | Средняя4,3 | — | 0,3 % | 11 сент. 2024 г. |
- CVE-2024-106142В плане
The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parame
КритическаяCVSS 9,8Proof of conceptEPSS 11 %bplugins · html5 video player30 янв. 2024 г.
- CVE-2023-4608435Наблюдать
WordPress Icons Font Loader Plugin <= 1.1.2 is vulnerable to SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bplugins · icons font loader6 нояб. 2023 г.
- CVE-2024-4329635Наблюдать
WordPress HTML5 Video Player plugin <= 2.5.30 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bplugins · html5 video player1 нояб. 2024 г.
- CVE-2025-2278735Наблюдать
WordPress Button Block plugin <= 1.1.5 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %bplugins · button block15 янв. 2025 г.
- CVE-2023-586028Наблюдать
Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bplugins · icons font loader2 нояб. 2023 г.
- CVE-2024-2471428Наблюдать
WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bplugins · icons font loader26 февр. 2024 г.
- CVE-2024-552227Наблюдать
HTML5 Video Player < 2.5.27 - Unauthenticated SQLi
СредняяCVSS 6,5Proof of conceptEPSS 3 %bplugins · html5 video player20 июн. 2024 г.
- CVE-2024-1067126Наблюдать
Button Block – Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bplugins · button block21 нояб. 2024 г.
- CVE-2024-1256026Наблюдать
Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication
СредняяCVSS 6,5Эксплойта нетEPSS 0 %bplugins · button block19 дек. 2024 г.
- CVE-2024-2350824Наблюдать
WordPress PDF Poster - PDF Embedder Plugin for WordPress Plugin <= 2.1.17 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %bplugins · pdf poster31 янв. 2024 г.
- CVE-2021-2477521Наблюдать
Document Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosure
СредняяCVSS 5,3Эксплойта нетEPSS 1 %bplugins · document embedder1 февр. 2022 г.
- CVE-2021-2441221Наблюдать
Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bplugins · html5 audio player18 окт. 2021 г.
- CVE-2021-2441321Наблюдать
Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bplugins · easy twitter feed18 окт. 2021 г.
- CVE-2021-2441621Наблюдать
StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bplugins · streamcast radio player18 окт. 2021 г.
- CVE-2021-2441521Наблюдать
Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bplugins · polo video gallery18 окт. 2021 г.
- CVE-2023-017021Наблюдать
Html5 Audio Player < 2.1.12 - Contributor+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bplugins · html5 audio player6 февр. 2023 г.
- CVE-2023-648521Наблюдать
Html5 Video Player < 2.5.19 - Subscriber+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %bplugins · html5 video player1 янв. 2024 г.
- CVE-2024-772721Наблюдать
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler
СредняяCVSS 5,3Эксплойта нетEPSS 0 %bplugins · html5 video player11 сент. 2024 г.
- CVE-2024-3744521Наблюдать
WordPress HTML5 Audio Player plugin <= 2.2.23 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bplugins · html5 audio player22 июл. 2024 г.
- CVE-2025-2281521Наблюдать
WordPress Button Block plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %bplugins · button block9 янв. 2025 г.
- CVE-2021-2486817Наблюдать
Document Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosure
СредняяCVSS 4,3Эксплойта нетEPSS 1 %bplugins · document embedder1 февр. 2022 г.
- CVE-2024-772117Наблюдать
HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
СредняяCVSS 4,3Эксплойта нетEPSS 0 %bplugins · html5 video player11 сент. 2024 г.