Записи joedolson
4 опубликованных записей вендора joedolson.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2023-6360Proof of concept | The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' pajoedolson · my calendar · CWE-89 | Критическая9,8 | — | 63,1 % | 30 нояб. 2023 г. |
21Наблюдать | CVE-2024-1274Эксплойта нет | My Calendar < 3.4.24 - Authenticated Stored XSSjoedolson · my calendar · CWE-79 | Средняя5,4 | — | 0,4 % | 2 апр. 2024 г. |
19Наблюдать | CVE-2023-34377Эксплойта нет | WordPress My Content Management Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)joedolson · my content management · CWE-79 | Средняя4,8 | — | 0,4 % | 5 авг. 2023 г. |
11Наблюдать | CVE-2012-6527Эксплойта нет | Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary wwordpress · wordpress · CWE-79 | Низкая2,6 | — | 2,2 % | 31 янв. 2013 г. |
- CVE-2023-636058В плане
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' pa
КритическаяCVSS 9,8Proof of conceptEPSS 63 %joedolson · my calendar30 нояб. 2023 г.
- CVE-2024-127421Наблюдать
My Calendar < 3.4.24 - Authenticated Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 0 %joedolson · my calendar2 апр. 2024 г.
- CVE-2023-3437719Наблюдать
WordPress My Content Management Plugin <= 1.7.6 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %joedolson · my content management5 авг. 2023 г.
- CVE-2012-652711Наблюдать
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary w
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %wordpress · wordpress31 янв. 2013 г.