Записи properfraction
35 опубликованных записей вендора properfraction.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 42,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-269 Improper Privilege Management3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-862 Missing Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
35 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2021-34621Proof of concept | ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalationproperfraction · profilepress · CWE-269 | Критическая9,8 | — | 68,9 % | 7 июл. 2021 г. |
41В плане | CVE-2021-34624Proof of concept | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Componentproperfraction · profilepress · CWE-434 | Критическая9,8 | — | 6,7 % | 7 июл. 2021 г. |
40В плане | CVE-2021-34623Эксплойта нет | ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Componentproperfraction · profilepress · CWE-434 | Критическая9,8 | — | 2,1 % | 7 июл. 2021 г. |
39Наблюдать | CVE-2024-9947Эксплойта нет | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth providerproperfraction · profilepress · CWE-287 | Критическая9,8 | — | 0,5 % | 23 окт. 2024 г. |
36Наблюдать | CVE-2021-34622Proof of concept | ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalationproperfraction · profilepress · CWE-269 | Высокая8,8 | — | 4,1 % | 7 июл. 2021 г. |
34Наблюдать | CVE-2023-41954Proof of concept | WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerabilityproperfraction · profilepress · CWE-269 | Высокая8,6 | — | 1,2 % | 17 мая 2024 г. |
30Наблюдать | CVE-2023-44150Эксплойта нет | WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposureproperfraction · profilepress · CWE-200 | Высокая7,5 | — | 0,7 % | 30 нояб. 2023 г. |
28Наблюдать | CVE-2022-45083Эксплойта нет | WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injectionproperfraction · profilepress · CWE-502 | Высокая7,2 | — | 0,6 % | 19 янв. 2024 г. |
24Наблюдать | CVE-2021-24522Proof of concept | ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widgetproperfraction · profilepress · CWE-79 | Средняя6,1 | — | 1,6 % | 9 авг. 2021 г. |
24Наблюдать | CVE-2024-1519Эксплойта нет | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Sproperfraction · profilepress · CWE-79 | Средняя6,1 | — | 0,6 % | 28 февр. 2024 г. |
24Наблюдать | CVE-2023-23830Эксплойта нет | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Средняя6,1 | — | 0,4 % | 3 мая 2023 г. |
24Наблюдать | CVE-2022-47444Эксплойта нет | WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Средняя6,1 | — | 0,4 % | 29 мар. 2023 г. |
21Наблюдать | CVE-2024-1408Эксплойта нет | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcodeproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,6 % | 28 февр. 2024 г. |
21Наблюдать | CVE-2024-1535Эксплойта нет | ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,6 % | 13 мар. 2024 г. |
21Наблюдать | CVE-2024-1806Эксплойта нет | ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcodeproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,6 % | 13 мар. 2024 г. |
21Наблюдать | CVE-2023-50882Эксплойта нет | WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerabilityproperfraction · profilepress · CWE-862 | Средняя5,3 | — | 0,5 % | 9 дек. 2024 г. |
21Наблюдать | CVE-2024-1570Эксплойта нет | ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,5 % | 28 февр. 2024 г. |
21Наблюдать | CVE-2024-1409Эксплойта нет | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,4 % | 13 мар. 2024 г. |
21Наблюдать | CVE-2024-3210Эксплойта нет | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,4 % | 10 апр. 2024 г. |
21Наблюдать | CVE-2023-41953Эксплойта нет | WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerabilityproperfraction · profilepress · CWE-862 | Средняя5,3 | — | 0,4 % | 9 дек. 2024 г. |
21Наблюдать | CVE-2023-23820Эксплойта нет | WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)properfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,4 % | 3 мая 2023 г. |
21Наблюдать | CVE-2024-11083Эксплойта нет | ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposureproperfraction · profilepress · CWE-200 | Средняя5,3 | — | 0,4 % | 27 нояб. 2024 г. |
21Наблюдать | CVE-2024-2867Эксплойта нет | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-20 | Средняя5,4 | — | 0,4 % | 2 мая 2024 г. |
21Наблюдать | CVE-2024-1046Эксплойта нет | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) Sproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,4 % | 5 февр. 2024 г. |
21Наблюдать | CVE-2024-2861Эксплойта нет | ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widgetproperfraction · profilepress · CWE-79 | Средняя5,4 | — | 0,3 % | 23 мая 2024 г. |
- CVE-2021-3462160На этой неделе
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
КритическаяCVSS 9,8Proof of conceptEPSS 69 %properfraction · profilepress7 июл. 2021 г.
- CVE-2021-3462441В плане
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component
КритическаяCVSS 9,8Proof of conceptEPSS 7 %properfraction · profilepress7 июл. 2021 г.
- CVE-2021-3462340В плане
ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in Image Uploader Component
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %properfraction · profilepress7 июл. 2021 г.
- CVE-2024-994739Наблюдать
ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %properfraction · profilepress23 окт. 2024 г.
- CVE-2021-3462236Наблюдать
ProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %properfraction · profilepress7 июл. 2021 г.
- CVE-2023-4195434Наблюдать
WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
ВысокаяCVSS 8,6Proof of conceptEPSS 1 %properfraction · profilepress17 мая 2024 г.
- CVE-2023-4415030Наблюдать
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %properfraction · profilepress30 нояб. 2023 г.
- CVE-2022-4508328Наблюдать
WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %properfraction · profilepress19 янв. 2024 г.
- CVE-2021-2452224Наблюдать
ProfilePress < 3.1.11 - Unauthenticated Cross-Site Scripting (XSS) in tabbed login/register widget
СредняяCVSS 6,1Proof of conceptEPSS 2 %properfraction · profilepress9 авг. 2021 г.
- CVE-2024-151924Наблюдать
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-S
СредняяCVSS 6,1Эксплойта нетEPSS 1 %properfraction · profilepress28 февр. 2024 г.
- CVE-2023-2383024Наблюдать
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %properfraction · profilepress3 мая 2023 г.
- CVE-2022-4744424Наблюдать
WordPress ProfilePress Plugin <= 4.4.1 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %properfraction · profilepress29 мар. 2023 г.
- CVE-2024-140821Наблюдать
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via [edit-profile-text-box] shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 1 %properfraction · profilepress28 февр. 2024 г.
- CVE-2024-153521Наблюдать
ProfilePress <= 4.15.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 1 %properfraction · profilepress13 мар. 2024 г.
- CVE-2024-180621Наблюдать
ProfilePress <= 4.15.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 1 %properfraction · profilepress13 мар. 2024 г.
- CVE-2023-5088221Наблюдать
WordPress ProfilePress plugin <= 4.13.2 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 1 %properfraction · profilepress9 дек. 2024 г.
- CVE-2024-157021Наблюдать
ProfilePress <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress28 февр. 2024 г.
- CVE-2024-140921Наблюдать
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.0 - Authenticated (Contributor+) S
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress13 мар. 2024 г.
- CVE-2024-321021Наблюдать
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.5 - Authenticated (Contributor+) S
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress10 апр. 2024 г.
- CVE-2023-4195321Наблюдать
WordPress ProfilePress plugin <= 4.13.1 - Broken Access Control vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %properfraction · profilepress9 дек. 2024 г.
- CVE-2023-2382021Наблюдать
WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress3 мая 2023 г.
- CVE-2024-1108321Наблюдать
ProfilePress <= 4.15.18 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %properfraction · profilepress27 нояб. 2024 г.
- CVE-2024-286721Наблюдать
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.15.4 - Authenticated (Contributor+) S
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress2 мая 2024 г.
- CVE-2024-104621Наблюдать
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.3 - Authenticated (Contributor+) S
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress5 февр. 2024 г.
- CVE-2024-286121Наблюдать
ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget
СредняяCVSS 5,4Эксплойта нетEPSS 0 %properfraction · profilepress23 мая 2024 г.