Записи LiquidWeb
11 опубликованных записей вендора liquidweb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 45,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2019-16120Эксплойта нет | CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Expoliquidweb · event tickets · CWE-1236 | Высокая8,8 | — | 3,2 % | 8 сент. 2019 г. |
30Наблюдать | CVE-2023-47668Proof of concept | WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposureliquidweb · restrict content · CWE-200 | Высокая7,5 | — | 1,0 % | 22 нояб. 2023 г. |
30Наблюдать | CVE-2025-14844Эксплойта нет | Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposureliquidweb · restrict content · CWE-639 | Высокая7,5 | — | 0,5 % | 16 янв. 2026 г. |
30Наблюдать | CVE-2024-11090Эксплойта нет | Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposureliquidweb · restrict content · CWE-200 | Высокая7,5 | — | 0,5 % | 26 янв. 2025 г. |
26Наблюдать | CVE-2024-1316Эксплойта нет | Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Accessliquidweb · event tickets · CWE-284 | Средняя6,5 | — | 0,6 % | 4 мар. 2024 г. |
24Наблюдать | CVE-2022-45825Эксплойта нет | WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)liquidweb · wpcomplete · CWE-79 | Средняя6,1 | — | 0,5 % | 28 мар. 2023 г. |
24Наблюдать | CVE-2023-3182Эксплойта нет | Membership Plugin - Restrict Content < 3.2.3 - Reflected XSSliquidweb · restrict content · CWE-79 | Средняя6,1 | — | 0,5 % | 17 июл. 2023 г. |
21Наблюдать | CVE-2024-31432Эксплойта нет | WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerabilitystellarwp · restrict content · CWE-862 | Средняя5,3 | — | 0,4 % | 15 апр. 2024 г. |
21Наблюдать | CVE-2024-13457Эксплойта нет | Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposureliquidweb · event tickets · CWE-284 | Средняя5,3 | — | 0,3 % | 30 янв. 2025 г. |
17Наблюдать | CVE-2024-1319Эксплойта нет | Event Tickets Plus < 5.9.1 - Contributor+ Attendees Lists Disclosureliquidweb · event tickets · CWE-284 | Средняя4,3 | — | 0,5 % | 4 мар. 2024 г. |
17Наблюдать | CVE-2024-1053Эксплойта нет | Event Tickets and Registration <= 5.8.1 - Missing Authorizationliquidweb · event tickets · CWE-284 | Средняя4,3 | — | 0,4 % | 22 февр. 2024 г. |
- CVE-2019-1612036Наблюдать
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Expo
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %liquidweb · event tickets8 сент. 2019 г.
- CVE-2023-4766830Наблюдать
WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposure
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %liquidweb · restrict content22 нояб. 2023 г.
- CVE-2025-1484430Наблюдать
Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %liquidweb · restrict content16 янв. 2026 г.
- CVE-2024-1109030Наблюдать
Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %liquidweb · restrict content26 янв. 2025 г.
- CVE-2024-131626Наблюдать
Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Access
СредняяCVSS 6,5Эксплойта нетEPSS 1 %liquidweb · event tickets4 мар. 2024 г.
- CVE-2022-4582524Наблюдать
WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 1 %liquidweb · wpcomplete28 мар. 2023 г.
- CVE-2023-318224Наблюдать
Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS
СредняяCVSS 6,1Эксплойта нетEPSS 0 %liquidweb · restrict content17 июл. 2023 г.
- CVE-2024-3143221Наблюдать
WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %stellarwp · restrict content15 апр. 2024 г.
- CVE-2024-1345721Наблюдать
Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %liquidweb · event tickets30 янв. 2025 г.
- CVE-2024-131917Наблюдать
Event Tickets Plus < 5.9.1 - Contributor+ Attendees Lists Disclosure
СредняяCVSS 4,3Эксплойта нетEPSS 0 %liquidweb · event tickets4 мар. 2024 г.
- CVE-2024-105317Наблюдать
Event Tickets and Registration <= 5.8.1 - Missing Authorization
СредняяCVSS 4,3Эксплойта нетEPSS 0 %liquidweb · event tickets22 февр. 2024 г.