Перейти к содержимому
Noroxi

Записи Etoilewebdesign

26 опубликованных записей вендора etoilewebdesign.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
23,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

26 записей
  • CVE-2025-2005
    46В плане

    Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload

    КритическаяCVSS 9,8Proof of conceptEPSS 22 %

    etoilewebdesign · front end users2 апр. 2025 г.

  • CVE-2017-12199
    40В плане

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    etoilewebdesign · ultimate product catalog2 авг. 2017 г.

  • CVE-2020-36726
    39Наблюдать

    Ultimate Reviews < 2.1.33 - PHP Object Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    etoilewebdesign · ultimate reviews6 июн. 2023 г.

  • CVE-2025-47580
    39Наблюдать

    WordPress Front End Users plugin <= 3.2.35 - Broken Access Control vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users15 мая 2025 г.

  • CVE-2024-7607
    35Наблюдать

    Front End Users <= 3.2.28 - Authenticated (Contributor+) Time-Based SQL Injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    etoilewebdesign · front end users29 авг. 2024 г.

  • CVE-2024-43343
    35Наблюдать

    WordPress Order Tracking – WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    etoilewebdesign · order tracking1 нояб. 2024 г.

  • CVE-2023-34005
    35Наблюдать

    WordPress Front End Users Plugin <= 3.2.24 is vulnerable to Cross Site Request Forgery (CSRF)

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users17 июл. 2023 г.

  • CVE-2019-17232
    31Наблюдать

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

    ВысокаяCVSS 7,5Proof of conceptEPSS 4 %

    etoilewebdesign · ultimate faq7 окт. 2019 г.

  • CVE-2024-13569
    28Наблюдать

    Front End Users <= 3.2.32 - Reflected XSS

    ВысокаяCVSS 7,1Proof of conceptEPSS 1 %

    etoilewebdesign · front end users22 апр. 2025 г.

  • CVE-2021-24993
    26Наблюдать

    Ultimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Update

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    etoilewebdesign · ultimate product catalog7 февр. 2022 г.

  • CVE-2020-7107
    25Наблюдать

    The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    etoilewebdesign · ultimate faq16 янв. 2020 г.

  • CVE-2019-17233
    25Наблюдать

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    etoilewebdesign · ultimate faq7 окт. 2019 г.

  • CVE-2020-24313
    24Наблюдать

    Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointmen

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etoilewebdesign · ultimate appointment booking \& scheduling26 авг. 2020 г.

  • CVE-2019-15643
    24Наблюдать

    The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etoilewebdesign · ultimate faq27 авг. 2019 г.

  • CVE-2017-12200
    24Наблюдать

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etoilewebdesign · ultimate product catalog2 авг. 2017 г.

  • CVE-2023-4471
    24Наблюдать

    Order Tracking Pro <= 3.3.6 - Reflected Cross-Site Scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    etoilewebdesign · order tracking31 авг. 2023 г.

  • CVE-2023-33322
    24Наблюдать

    WordPress Front End Users plugin < 3.2.25 - Cross Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users26 мар. 2024 г.

  • CVE-2024-25597
    24Наблюдать

    WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    etoilewebdesign · ultimate reviews15 мар. 2024 г.

  • CVE-2021-24968
    22Наблюдать

    Ultimate FAQ < 2.1.2 - Subscriber+ Arbitrary FAQ Creation

    СредняяCVSS 5,7Эксплойта нетEPSS 0 %

    etoilewebdesign · ultimate faq24 янв. 2022 г.

  • CVE-2024-7606
    21Наблюдать

    Front End Users <= 3.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users29 авг. 2024 г.

  • CVE-2024-13563
    21Наблюдать

    Front End Users <= 3.2.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via forgot-password Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users15 февр. 2025 г.

  • CVE-2025-26877
    21Наблюдать

    WordPress Front End Users Plugin <= 3.2.30 - Cross Site Scripting (XSS) vulnerability

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users25 февр. 2025 г.

  • CVE-2022-23979
    19Наблюдать

    WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    etoilewebdesign · ultimate reviews28 янв. 2022 г.

  • CVE-2023-2711
    19Наблюдать

    Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSS

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    etoilewebdesign · ultimate product catalog27 июн. 2023 г.

  • CVE-2024-12410
    19Наблюдать

    Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injection

    СредняяCVSS 4,9Эксплойта нетEPSS 0 %

    etoilewebdesign · front end users2 апр. 2025 г.