Перейти к содержимому
Noroxi

Записи plugin-planet

22 опубликованных записей вендора plugin-planet.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
40,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

22 записей
  • CVE-2019-25138
    40В плане

    User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    plugin-planet · user submitted posts6 июн. 2023 г.

  • CVE-2023-45603
    39Наблюдать

    WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Upload

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    plugin-planet · user submitted posts20 дек. 2023 г.

  • CVE-2022-1165
    37Наблюдать

    Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofing

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    plugin-planet · blackhole for bad bots4 апр. 2022 г.

  • CVE-2022-27849
    31Наблюдать

    WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability

    ВысокаяCVSS 7,5Proof of conceptEPSS 5 %

    plugin-planet · simple ajax chat15 апр. 2022 г.

  • CVE-2024-1983
    28Наблюдать

    Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    plugin-planet · simple ajax chat20 мар. 2024 г.

  • CVE-2021-24409
    25Наблюдать

    Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    plugin-planet · prismatic12 июл. 2021 г.

  • CVE-2016-11001
    24Наблюдать

    The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    plugin-planet · user submitted posts20 сент. 2019 г.

  • CVE-2022-25601
    24Наблюдать

    WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    plugin-planet · contact form x11 мар. 2022 г.

  • CVE-2022-25610
    24Наблюдать

    WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    plugin-planet · simple ajax chat25 мар. 2022 г.

  • CVE-2024-0979
    24Наблюдать

    Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    plugin-planet · dashboard widgets suite13 июн. 2024 г.

  • CVE-2021-24408
    21Наблюдать

    Prismatic < 2.8 - Contributor+ Stored XSS

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    plugin-planet · prismatic12 июл. 2021 г.

  • CVE-2023-5614
    21Наблюдать

    Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · theme switcha20 окт. 2023 г.

  • CVE-2023-4308
    21Наблюдать

    User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · user submitted posts15 авг. 2023 г.

  • CVE-2023-4779
    21Наблюдать

    User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · user submitted posts6 сент. 2023 г.

  • CVE-2023-4838
    21Наблюдать

    The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · simple download counter8 сент. 2023 г.

  • CVE-2024-2470
    21Наблюдать

    Simple Ajax Chat < 20240412 - Admin+ Stored XSS

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · simple ajax chat4 июн. 2024 г.

  • CVE-2025-46240
    21Наблюдать

    WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · simple download counter22 апр. 2025 г.

  • CVE-2025-46239
    21Наблюдать

    WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    plugin-planet · theme switcha22 апр. 2025 г.

  • CVE-2024-5002
    19Наблюдать

    User Submitted Posts < 20240516 - Admin+ Stored XSS

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    plugin-planet · user submitted posts13 июл. 2024 г.

  • CVE-2023-49743
    19Наблюдать

    WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    plugin-planet · dashboard widget suite14 дек. 2023 г.

  • CVE-2023-26517
    19Наблюдать

    WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    plugin-planet · dashboard widget suite6 мая 2023 г.

  • CVE-2022-27850
    17Наблюдать

    WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    plugin-planet · simple ajax chat15 апр. 2022 г.