Записи codection
18 опубликованных записей вендора codection.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 11,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-201 Insertion of Sensitive Information Into Sent Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2024-8252Proof of concept | Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusioncodection · clean login · CWE-98 | Высокая8,8 | — | 3,0 % | 30 авг. 2024 г. |
35Наблюдать | CVE-2019-15329Эксплойта нет | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.codection · import users from csv with meta · CWE-352 | Высокая8,8 | — | 0,7 % | 22 авг. 2019 г. |
33Наблюдать | CVE-2020-22277Эксплойта нет | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.codection · import and export users and customers · CWE-1236 | Высокая8,0 | — | 1,9 % | 4 нояб. 2020 г. |
32Наблюдать | CVE-2022-3558Эксплойта нет | Import and export users and customers < 1.20.5 - Subscriber+ CSV Injectioncodection · import and export users and customers · CWE-1236 | Высокая8,0 | — | 1,1 % | 7 нояб. 2022 г. |
31Наблюдать | CVE-2019-15326Эксплойта нет | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.codection · import users from csv with meta · CWE-22 | Высокая7,5 | — | 2,3 % | 22 авг. 2019 г. |
30Наблюдать | CVE-2024-38787Эксплойта нет | WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerabilityjavier carazo · import and export users and customers · CWE-201 | Высокая7,5 | — | 0,4 % | 13 авг. 2024 г. |
28Наблюдать | CVE-2023-6583Эксплойта нет | Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionalitycodection · import and export users and customers · CWE-98 | Высокая7,2 | — | 0,8 % | 11 янв. 2024 г. |
26Наблюдать | CVE-2017-8875Эксплойта нет | CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.codection · clean login · CWE-352 | Средняя6,5 | — | 0,6 % | 10 мая 2017 г. |
24Наблюдать | CVE-2019-15328Эксплойта нет | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.codection · import users from csv with meta · CWE-79 | Средняя6,1 | — | 0,9 % | 22 авг. 2019 г. |
24Наблюдать | CVE-2015-9336Эксплойта нет | The clean-login plugin before 1.5.1 for WordPress has reflected XSS.codection · clean login · CWE-79 | Средняя6,1 | — | 0,9 % | 22 авг. 2019 г. |
24Наблюдать | CVE-2019-15327Эксплойта нет | The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.codection · import users from csv with meta · CWE-79 | Средняя6,1 | — | 0,9 % | 22 авг. 2019 г. |
24Наблюдать | CVE-2018-20101Эксплойта нет | The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.codection · import users from csv with meta · CWE-79 | Средняя6,1 | — | 0,8 % | 12 дек. 2018 г. |
22Наблюдать | CVE-2019-14683Эксплойта нет | The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attaccodection · import users from csv with meta · CWE-352 | Средняя5,7 | — | 0,7 % | 8 авг. 2019 г. |
21Наблюдать | CVE-2022-4838Эксплойта нет | Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcodecodection · clean login · CWE-79 | Средняя5,4 | — | 0,6 % | 6 февр. 2023 г. |
21Наблюдать | CVE-2023-6624Эксплойта нет | Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcodecodection · import and export users and customers · CWE-79 | Средняя5,4 | — | 0,3 % | 11 янв. 2024 г. |
21Наблюдать | CVE-2024-22151Эксплойта нет | WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerabilitycodection · import and export users and customers · CWE-862 | Средняя5,3 | — | 0,3 % | 8 июн. 2024 г. |
19Наблюдать | CVE-2022-1255Эксплойта нет | Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scriptingcodection · import and export users and customers · CWE-79 | Средняя4,8 | — | 0,7 % | 2 мая 2022 г. |
17Наблюдать | CVE-2024-4734Эксплойта нет | Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scriptingcarazo · import and export users and customers · CWE-79 | Средняя4,4 | — | 0,3 % | 14 мая 2024 г. |
- CVE-2024-825236Наблюдать
Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %codection · clean login30 авг. 2024 г.
- CVE-2019-1532935Наблюдать
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %codection · import users from csv with meta22 авг. 2019 г.
- CVE-2020-2227733Наблюдать
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %codection · import and export users and customers4 нояб. 2020 г.
- CVE-2022-355832Наблюдать
Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %codection · import and export users and customers7 нояб. 2022 г.
- CVE-2019-1532631Наблюдать
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %codection · import users from csv with meta22 авг. 2019 г.
- CVE-2024-3878730Наблюдать
WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %javier carazo · import and export users and customers13 авг. 2024 г.
- CVE-2023-658328Наблюдать
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %codection · import and export users and customers11 янв. 2024 г.
- CVE-2017-887526Наблюдать
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %codection · clean login10 мая 2017 г.
- CVE-2019-1532824Наблюдать
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %codection · import users from csv with meta22 авг. 2019 г.
- CVE-2015-933624Наблюдать
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %codection · clean login22 авг. 2019 г.
- CVE-2019-1532724Наблюдать
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %codection · import users from csv with meta22 авг. 2019 г.
- CVE-2018-2010124Наблюдать
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %codection · import users from csv with meta12 дек. 2018 г.
- CVE-2019-1468322Наблюдать
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac
СредняяCVSS 5,7Эксплойта нетEPSS 1 %codection · import users from csv with meta8 авг. 2019 г.
- CVE-2022-483821Наблюдать
Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 1 %codection · clean login6 февр. 2023 г.
- CVE-2023-662421Наблюдать
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 0 %codection · import and export users and customers11 янв. 2024 г.
- CVE-2024-2215121Наблюдать
WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %codection · import and export users and customers8 июн. 2024 г.
- CVE-2022-125519Наблюдать
Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting
СредняяCVSS 4,8Эксплойта нетEPSS 1 %codection · import and export users and customers2 мая 2022 г.
- CVE-2024-473417Наблюдать
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
СредняяCVSS 4,4Эксплойта нетEPSS 0 %carazo · import and export users and customers14 мая 2024 г.