Перейти к содержимому
Noroxi

Записи codection

18 опубликованных записей вендора codection.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
11,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

18 записей
  • CVE-2024-8252
    36Наблюдать

    Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    codection · clean login30 авг. 2024 г.

  • CVE-2019-15329
    35Наблюдать

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    codection · import users from csv with meta22 авг. 2019 г.

  • CVE-2020-22277
    33Наблюдать

    Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %

    codection · import and export users and customers4 нояб. 2020 г.

  • CVE-2022-3558
    32Наблюдать

    Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    codection · import and export users and customers7 нояб. 2022 г.

  • CVE-2019-15326
    31Наблюдать

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    codection · import users from csv with meta22 авг. 2019 г.

  • CVE-2024-38787
    30Наблюдать

    WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    javier carazo · import and export users and customers13 авг. 2024 г.

  • CVE-2023-6583
    28Наблюдать

    Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    codection · import and export users and customers11 янв. 2024 г.

  • CVE-2017-8875
    26Наблюдать

    CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    codection · clean login10 мая 2017 г.

  • CVE-2019-15328
    24Наблюдать

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    codection · import users from csv with meta22 авг. 2019 г.

  • CVE-2015-9336
    24Наблюдать

    The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    codection · clean login22 авг. 2019 г.

  • CVE-2019-15327
    24Наблюдать

    The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    codection · import users from csv with meta22 авг. 2019 г.

  • CVE-2018-20101
    24Наблюдать

    The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    codection · import users from csv with meta12 дек. 2018 г.

  • CVE-2019-14683
    22Наблюдать

    The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac

    СредняяCVSS 5,7Эксплойта нетEPSS 1 %

    codection · import users from csv with meta8 авг. 2019 г.

  • CVE-2022-4838
    21Наблюдать

    Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    codection · clean login6 февр. 2023 г.

  • CVE-2023-6624
    21Наблюдать

    Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    codection · import and export users and customers11 янв. 2024 г.

  • CVE-2024-22151
    21Наблюдать

    WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    codection · import and export users and customers8 июн. 2024 г.

  • CVE-2022-1255
    19Наблюдать

    Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    codection · import and export users and customers2 мая 2022 г.

  • CVE-2024-4734
    17Наблюдать

    Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    carazo · import and export users and customers14 мая 2024 г.