Записи coolplugins
12 опубликованных записей вендора coolplugins.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-36681Эксплойта нет | WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerabilitycoolplugins · cryptocurrency widgets · CWE-862 | Критическая9,8 | — | 0,9 % | 13 дек. 2024 г. |
39Наблюдать | CVE-2024-53739Эксплойта нет | WordPress Cryptocurrency Widgets For Elementor plugin <= 1.6.4 - Local File Inclusion vulnerabilitycoolplugins · cryptocurrency widgets for elementor · CWE-98 | Критическая9,8 | — | 0,7 % | 30 нояб. 2024 г. |
35Наблюдать | CVE-2022-4950Эксплойта нет | Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activationcoolplugins · cool timeline · CWE-862 | Высокая8,8 | — | 1,4 % | 6 июн. 2023 г. |
35Наблюдать | CVE-2021-4349Эксплойта нет | Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgerycoolplugins · process steps template designer · CWE-352 | Высокая8,8 | — | 0,6 % | 6 июн. 2023 г. |
35Наблюдать | CVE-2023-52142Эксплойта нет | WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injectioncoolplugins · events shortcodes for the events calendar · CWE-89 | Высокая8,8 | — | 0,5 % | 8 янв. 2024 г. |
30Наблюдать | CVE-2024-0709Эксплойта нет | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in coolplugins · cryptocurrency widgets · CWE-89 | Высокая7,5 | — | 0,9 % | 5 февр. 2024 г. |
24Наблюдать | CVE-2024-43304Эксплойта нет | WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerabilitycoolplugins · cryptocurrency widgets · CWE-79 | Средняя6,1 | — | 0,3 % | 18 авг. 2024 г. |
21Наблюдать | CVE-2024-0977Эксплойта нет | Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scriptingcoolplugins · timeline widget for elementor · CWE-79 | Средняя5,4 | — | 0,3 % | 7 февр. 2024 г. |
21Наблюдать | CVE-2024-52354Эксплойта нет | WordPress Web Stories Widgets For Elementor plugin <= 1.1 - Cross Site Scripting (XSS) vulnerabilitycoolplugins · web stories widgets for elementor · CWE-79 | Средняя5,4 | — | 0,3 % | 11 нояб. 2024 г. |
18Наблюдать | CVE-2024-27953Эксплойта нет | WordPress Cryptocurrency Widgets – Price Ticker & Coins List Plugin <= 2.6.8 is vulnerable to Broken Access Controlcoolplugins · cryptocurrency widgets · CWE-862 | Средняя4,7 | — | 0,4 % | 13 мар. 2024 г. |
17Наблюдать | CVE-2020-36738Эксплойта нет | Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery Bypasscoolplugins · cool timeline · CWE-352 | Средняя4,3 | — | 0,5 % | 1 июл. 2023 г. |
17Наблюдать | CVE-2021-4413Эксплойта нет | Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery Bypasscoolplugins · process steps template designer · CWE-352 | Средняя4,3 | — | 0,4 % | 12 июл. 2023 г. |
- CVE-2023-3668139Наблюдать
WordPress Cryptocurrency Widgets – Price Ticker & Coins List plugin <= 2.6.2 - Broken Access Control vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %coolplugins · cryptocurrency widgets13 дек. 2024 г.
- CVE-2024-5373939Наблюдать
WordPress Cryptocurrency Widgets For Elementor plugin <= 1.6.4 - Local File Inclusion vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %coolplugins · cryptocurrency widgets for elementor30 нояб. 2024 г.
- CVE-2022-495035Наблюдать
Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %coolplugins · cool timeline6 июн. 2023 г.
- CVE-2021-434935Наблюдать
Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %coolplugins · process steps template designer6 июн. 2023 г.
- CVE-2023-5214235Наблюдать
WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %coolplugins · events shortcodes for the events calendar8 янв. 2024 г.
- CVE-2024-070930Наблюдать
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %coolplugins · cryptocurrency widgets5 февр. 2024 г.
- CVE-2024-4330424Наблюдать
WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %coolplugins · cryptocurrency widgets18 авг. 2024 г.
- CVE-2024-097721Наблюдать
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %coolplugins · timeline widget for elementor7 февр. 2024 г.
- CVE-2024-5235421Наблюдать
WordPress Web Stories Widgets For Elementor plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %coolplugins · web stories widgets for elementor11 нояб. 2024 г.
- CVE-2024-2795318Наблюдать
WordPress Cryptocurrency Widgets – Price Ticker & Coins List Plugin <= 2.6.8 is vulnerable to Broken Access Control
СредняяCVSS 4,7Эксплойта нетEPSS 0 %coolplugins · cryptocurrency widgets13 мар. 2024 г.
- CVE-2020-3673817Наблюдать
Cool Timeline (Horizontal & Vertical Timeline) <= 2.0.2 - Cross-Site Request Forgery Bypass
СредняяCVSS 4,3Эксплойта нетEPSS 0 %coolplugins · cool timeline1 июл. 2023 г.
- CVE-2021-441317Наблюдать
Process Steps Template Designer <= 1.2.1 - Cross-Site Request Forgery Bypass
СредняяCVSS 4,3Эксплойта нетEPSS 0 %coolplugins · process steps template designer12 июл. 2023 г.