Перейти к содержимому
Noroxi

Записи iptanus

25 опубликованных записей вендора iptanus.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
12 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

25 записей
  • CVE-2024-9047
    67На этой неделе

    WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php

    КритическаяCVSS 9,8Proof of conceptEPSS 93 %

    iptanus · wordpress file upload12 окт. 2024 г.

  • CVE-2020-10564
    42В плане

    An issue was discovered in the File Upload plugin before 4.13.0 for WordPress.

    КритическаяCVSS 9,8Эксплойта нетEPSS 9 %

    iptanus · wordpress file upload13 мар. 2020 г.

  • CVE-2024-11613
    40В плане

    WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    iptanus · wordpress file upload8 янв. 2025 г.

  • CVE-2024-11635
    39Наблюдать

    WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    iptanus · wordpress file upload8 янв. 2025 г.

  • CVE-2021-24962
    36Наблюдать

    WordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCE

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    iptanus · wordpress file upload28 мар. 2022 г.

  • CVE-2015-9338
    30Наблюдать

    The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload22 авг. 2019 г.

  • CVE-2015-9341
    30Наблюдать

    The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload22 авг. 2019 г.

  • CVE-2015-9340
    30Наблюдать

    The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm,

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload22 авг. 2019 г.

  • CVE-2015-9339
    30Наблюдать

    The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload22 авг. 2019 г.

  • CVE-2024-9939
    30Наблюдать

    WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload8 янв. 2025 г.

  • CVE-2024-6651
    29Наблюдать

    WordPress File Upload < 4.24.8 - Reflected XSS

    СредняяCVSS 6,1Proof of conceptEPSS 15 %

    iptanus · wordpress file upload6 авг. 2024 г.

  • CVE-2018-9844
    25Наблюдать

    The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    iptanus · wordpress file upload7 апр. 2018 г.

  • CVE-2024-7301
    24Наблюдать

    WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload16 авг. 2024 г.

  • CVE-2024-6494
    24Наблюдать

    WordPress File Upload < 4.24.8 - Unauthenticated Stored XSS

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload7 авг. 2024 г.

  • CVE-2018-9172
    22Наблюдать

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

    СредняяCVSS 5,4Proof of conceptEPSS 3 %

    iptanus · wordpress file upload1 апр. 2018 г.

  • CVE-2023-2767
    22Наблюдать

    WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload9 июн. 2023 г.

  • CVE-2021-24960
    21Наблюдать

    WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Malicious SVG

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload7 мар. 2022 г.

  • CVE-2021-24961
    21Наблюдать

    WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload7 мар. 2022 г.

  • CVE-2023-4811
    21Наблюдать

    WordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload16 окт. 2023 г.

  • CVE-2024-2847
    21Наблюдать

    WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload9 апр. 2024 г.

  • CVE-2023-2688
    20Наблюдать

    WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal

    СредняяCVSS 4,9Эксплойта нетEPSS 2 %

    iptanus · wordpress file upload9 июн. 2023 г.

  • CVE-2024-5852
    17Наблюдать

    WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    iptanus · wordpress file upload16 июл. 2024 г.

  • CVE-2024-12719
    17Наблюдать

    WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload7 янв. 2025 г.

  • CVE-2024-13494
    17Наблюдать

    WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload25 февр. 2025 г.

  • CVE-2024-39639
    14Наблюдать

    WordPress File Upload plugin <= 4.24.7 - Broken Access Control + CSRF vulnerability

    НизкаяCVSS 3,5Эксплойта нетEPSS 0 %

    iptanus · wordpress file upload1 нояб. 2024 г.