Записи plugin-planet
22 опубликованных записей вендора plugin-planet.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 40,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-25138Эксплойта нет | User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Uploadplugin-planet · user submitted posts · CWE-434 | Критическая9,8 | — | 2,3 % | 6 июн. 2023 г. |
39Наблюдать | CVE-2023-45603Эксплойта нет | WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Uploadplugin-planet · user submitted posts · CWE-434 | Критическая9,8 | — | 0,9 % | 20 дек. 2023 г. |
37Наблюдать | CVE-2022-1165Эксплойта нет | Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofingplugin-planet · blackhole for bad bots · CWE-639 | Критическая9,1 | — | 1,7 % | 4 апр. 2022 г. |
31Наблюдать | CVE-2022-27849Proof of concept | WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerabilityplugin-planet · simple ajax chat · CWE-200 | Высокая7,5 | — | 4,6 % | 15 апр. 2022 г. |
28Наблюдать | CVE-2024-1983Эксплойта нет | Simple Ajax Chat < 20240223 - Unauthenticated Stored XSSplugin-planet · simple ajax chat · CWE-79 | Высокая7,1 | — | 0,5 % | 20 мар. 2024 г. |
25Наблюдать | CVE-2021-24409Proof of concept | Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)plugin-planet · prismatic · CWE-79 | Средняя6,1 | — | 1,7 % | 12 июл. 2021 г. |
24Наблюдать | CVE-2016-11001Эксплойта нет | The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.plugin-planet · user submitted posts · CWE-79 | Средняя6,1 | — | 1,2 % | 20 сент. 2019 г. |
24Наблюдать | CVE-2022-25601Эксплойта нет | WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerabilityplugin-planet · contact form x · CWE-79 | Средняя6,1 | — | 1,0 % | 11 мар. 2022 г. |
24Наблюдать | CVE-2022-25610Эксплойта нет | WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilityplugin-planet · simple ajax chat · CWE-79 | Средняя6,1 | — | 0,7 % | 25 мар. 2022 г. |
24Наблюдать | CVE-2024-0979Эксплойта нет | Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scriptingplugin-planet · dashboard widgets suite · CWE-79 | Средняя6,1 | — | 0,4 % | 13 июн. 2024 г. |
21Наблюдать | CVE-2021-24408Эксплойта нет | Prismatic < 2.8 - Contributor+ Stored XSSplugin-planet · prismatic · CWE-79 | Средняя5,4 | — | 0,6 % | 12 июл. 2021 г. |
21Наблюдать | CVE-2023-5614Эксплойта нет | Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeplugin-planet · theme switcha · CWE-79 | Средняя5,4 | — | 0,4 % | 20 окт. 2023 г. |
21Наблюдать | CVE-2023-4308Эксплойта нет | User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'plugin-planet · user submitted posts · CWE-79 | Средняя5,4 | — | 0,4 % | 15 авг. 2023 г. |
21Наблюдать | CVE-2023-4779Эксплойта нет | User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeplugin-planet · user submitted posts · CWE-79 | Средняя5,4 | — | 0,4 % | 6 сент. 2023 г. |
21Наблюдать | CVE-2023-4838Эксплойта нет | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,plugin-planet · simple download counter · CWE-79 | Средняя5,4 | — | 0,4 % | 8 сент. 2023 г. |
21Наблюдать | CVE-2024-2470Эксплойта нет | Simple Ajax Chat < 20240412 - Admin+ Stored XSSplugin-planet · simple ajax chat · CWE-79 | Средняя5,4 | — | 0,3 % | 4 июн. 2024 г. |
21Наблюдать | CVE-2025-46240Эксплойта нет | WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerabilityplugin-planet · simple download counter · CWE-79 | Средняя5,4 | — | 0,2 % | 22 апр. 2025 г. |
21Наблюдать | CVE-2025-46239Эксплойта нет | WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerabilityplugin-planet · theme switcha · CWE-79 | Средняя5,4 | — | 0,2 % | 22 апр. 2025 г. |
19Наблюдать | CVE-2024-5002Эксплойта нет | User Submitted Posts < 20240516 - Admin+ Stored XSSplugin-planet · user submitted posts · CWE-79 | Средняя4,8 | — | 0,4 % | 13 июл. 2024 г. |
19Наблюдать | CVE-2023-49743Эксплойта нет | WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)plugin-planet · dashboard widget suite · CWE-79 | Средняя4,8 | — | 0,4 % | 14 дек. 2023 г. |
19Наблюдать | CVE-2023-26517Эксплойта нет | WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)plugin-planet · dashboard widget suite · CWE-79 | Средняя4,8 | — | 0,4 % | 6 мая 2023 г. |
17Наблюдать | CVE-2022-27850Эксплойта нет | WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilityplugin-planet · simple ajax chat · CWE-352 | Средняя4,3 | — | 0,4 % | 15 апр. 2022 г. |
- CVE-2019-2513840В плане
User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %plugin-planet · user submitted posts6 июн. 2023 г.
- CVE-2023-4560339Наблюдать
WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Upload
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %plugin-planet · user submitted posts20 дек. 2023 г.
- CVE-2022-116537Наблюдать
Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofing
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %plugin-planet · blackhole for bad bots4 апр. 2022 г.
- CVE-2022-2784931Наблюдать
WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %plugin-planet · simple ajax chat15 апр. 2022 г.
- CVE-2024-198328Наблюдать
Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %plugin-planet · simple ajax chat20 мар. 2024 г.
- CVE-2021-2440925Наблюдать
Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)
СредняяCVSS 6,1Proof of conceptEPSS 2 %plugin-planet · prismatic12 июл. 2021 г.
- CVE-2016-1100124Наблюдать
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %plugin-planet · user submitted posts20 сент. 2019 г.
- CVE-2022-2560124Наблюдать
WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 1 %plugin-planet · contact form x11 мар. 2022 г.
- CVE-2022-2561024Наблюдать
WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 1 %plugin-planet · simple ajax chat25 мар. 2022 г.
- CVE-2024-097924Наблюдать
Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %plugin-planet · dashboard widgets suite13 июн. 2024 г.
- CVE-2021-2440821Наблюдать
Prismatic < 2.8 - Contributor+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %plugin-planet · prismatic12 июл. 2021 г.
- CVE-2023-561421Наблюдать
Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · theme switcha20 окт. 2023 г.
- CVE-2023-430821Наблюдать
User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · user submitted posts15 авг. 2023 г.
- CVE-2023-477921Наблюдать
User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · user submitted posts6 сент. 2023 г.
- CVE-2023-483821Наблюдать
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · simple download counter8 сент. 2023 г.
- CVE-2024-247021Наблюдать
Simple Ajax Chat < 20240412 - Admin+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · simple ajax chat4 июн. 2024 г.
- CVE-2025-4624021Наблюдать
WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · simple download counter22 апр. 2025 г.
- CVE-2025-4623921Наблюдать
WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %plugin-planet · theme switcha22 апр. 2025 г.
- CVE-2024-500219Наблюдать
User Submitted Posts < 20240516 - Admin+ Stored XSS
СредняяCVSS 4,8Эксплойта нетEPSS 0 %plugin-planet · user submitted posts13 июл. 2024 г.
- CVE-2023-4974319Наблюдать
WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %plugin-planet · dashboard widget suite14 дек. 2023 г.
- CVE-2023-2651719Наблюдать
WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 4,8Эксплойта нетEPSS 0 %plugin-planet · dashboard widget suite6 мая 2023 г.
- CVE-2022-2785017Наблюдать
WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability
СредняяCVSS 4,3Эксплойта нетEPSS 0 %plugin-planet · simple ajax chat15 апр. 2022 г.