Записи piwebsolution
10 опубликованных записей вендора piwebsolution.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-3603Эксплойта нет | Export customers list CSV for WooCommerce < 2.0.69 - CSV Injectionpiwebsolution · export customers list csv for woocommerce · CWE-1236 | Критическая9,8 | — | 1,1 % | 28 нояб. 2022 г. |
35Наблюдать | CVE-2024-8922Эксплойта нет | Product Enquiry for WooCommerce <= 2.2.33.33 - Authenticated (Author+) PHP Object Injection in enquiry_detail.phppiwebsolution · product enquiry for woocommerce · CWE-502 | Высокая8,8 | — | 0,8 % | 27 сент. 2024 г. |
35Наблюдать | CVE-2022-47154Эксплойта нет | WordPress CSS JS Manager Plugin <= 2.4.49 is vulnerable to Cross Site Request Forgery (CSRF)piwebsolution · css js manager\, async javascript\, defer render blocking css supports woocommerce · CWE-352 | Высокая8,8 | — | 0,3 % | 14 мар. 2023 г. |
35Наблюдать | CVE-2023-34015Эксплойта нет | WordPress Advanced Flat rate shipping Woocommerce Plugin <= 1.6.4.4 is vulnerable to Cross Site Request Forgery (CSRF)piwebsolution · advanced-free-flat-shipping-woocommerce · CWE-352 | Высокая8,8 | — | 0,2 % | 11 июл. 2023 г. |
19Наблюдать | CVE-2023-29093Эксплойта нет | WordPress Conditional extra fees for woocommerce Plugin <= 1.0.96 is vulnerable to Cross Site Scripting (XSS)piwebsolution · conditional cart fee \/ extra charge rule for woocommerce extra fees · CWE-79 | Средняя4,8 | — | 0,4 % | 26 июн. 2023 г. |
19Наблюдать | CVE-2023-29094Эксплойта нет | WordPress Product page shipping calculator for WooCommerce Plugin <= 1.3.20 is vulnerable to Cross Site Scripting (XSS)piwebsolution · product page shipping calculator for woocommerce · CWE-79 | Средняя4,8 | — | 0,4 % | 7 апр. 2023 г. |
19Наблюдать | CVE-2023-28988Эксплойта нет | WordPress Direct checkout, Add to cart redirect for Woocommerce Plugin <= 2.1.48 is vulnerable to Cross Site Scripting (XSS)piwebsolution · add-to-cart-direct-checkout-for-woocommerce · CWE-79 | Средняя4,8 | — | 0,4 % | 26 июн. 2023 г. |
19Наблюдать | CVE-2023-29423Эксплойта нет | WordPress Cancel order request WooCommerce Plugin <= 1.3.2 is vulnerable to Cross Site Scripting (XSS)piwebsolution · cancel order request \/ return order \/ repeat order \/ reorder for woocommerce · CWE-79 | Средняя4,8 | — | 0,4 % | 26 июн. 2023 г. |
19Наблюдать | CVE-2023-29170Эксплойта нет | WordPress Product Enquiry for WooCommerce Plugin <= 2.2.12 is vulnerable to Cross Site Scripting (XSS)piwebsolution · product enquiry for woocommerce · CWE-79 | Средняя4,8 | — | 0,4 % | 7 апр. 2023 г. |
19Наблюдать | CVE-2023-28991Эксплойта нет | WordPress Order date time for WooCommerce Plugin <= 3.0.19 is vulnerable to Cross Site Scripting (XSS)piwebsolution · pi-woocommerce-order-date-time-and-type · CWE-79 | Средняя4,8 | — | 0,4 % | 26 июн. 2023 г. |
- CVE-2022-360339Наблюдать
Export customers list CSV for WooCommerce < 2.0.69 - CSV Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %piwebsolution · export customers list csv for woocommerce28 нояб. 2022 г.
- CVE-2024-892235Наблюдать
Product Enquiry for WooCommerce <= 2.2.33.33 - Authenticated (Author+) PHP Object Injection in enquiry_detail.php
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %piwebsolution · product enquiry for woocommerce27 сент. 2024 г.
- CVE-2022-4715435Наблюдать
WordPress CSS JS Manager Plugin <= 2.4.49 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %piwebsolution · css js manager\, async javascript\, defer render blocking css supports woocommerce14 мар. 2023 г.
- CVE-2023-3401535Наблюдать
WordPress Advanced Flat rate shipping Woocommerce Plugin <= 1.6.4.4 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %piwebsolution · advanced-free-flat-shipping-woocommerce11 июл. 2023 г.
- CVE-2023-2909319Наблюдать
WordPress Conditional extra fees for woocommerce Plugin <= 1.0.96 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %piwebsolution · conditional cart fee \/ extra charge rule for woocommerce extra fees26 июн. 2023 г.
- CVE-2023-2909419Наблюдать
WordPress Product page shipping calculator for WooCommerce Plugin <= 1.3.20 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %piwebsolution · product page shipping calculator for woocommerce7 апр. 2023 г.
- CVE-2023-2898819Наблюдать
WordPress Direct checkout, Add to cart redirect for Woocommerce Plugin <= 2.1.48 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %piwebsolution · add-to-cart-direct-checkout-for-woocommerce26 июн. 2023 г.
- CVE-2023-2942319Наблюдать
WordPress Cancel order request WooCommerce Plugin <= 1.3.2 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %piwebsolution · cancel order request \/ return order \/ repeat order \/ reorder for woocommerce26 июн. 2023 г.
- CVE-2023-2917019Наблюдать
WordPress Product Enquiry for WooCommerce Plugin <= 2.2.12 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %piwebsolution · product enquiry for woocommerce7 апр. 2023 г.
- CVE-2023-2899119Наблюдать
WordPress Order date time for WooCommerce Plugin <= 3.0.19 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %piwebsolution · pi-woocommerce-order-date-time-and-type26 июн. 2023 г.