Записи smackcoders
24 опубликованных записей вендора smackcoders.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 4,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2016-11000Эксплойта нет | The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.smackcoders · ultimate exporter · CWE-89 | Критическая9,8 | — | 2,1 % | 20 сент. 2019 г. |
40В плане | CVE-2024-43965Proof of concept | WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerabilitysmackcoders · sendgrid · CWE-89 | Критическая9,8 | — | 2,0 % | 29 авг. 2024 г. |
35Наблюдать | CVE-2023-4141Эксплойта нет | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Executionsmackcoders · wp ultimate csv importer · CWE-94 | Высокая8,8 | — | 1,6 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2023-4142Эксплойта нет | WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Executionsmackcoders · wp ultimate csv importer · CWE-94 | Высокая8,8 | — | 1,6 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2022-3860Эксплойта нет | Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLismackcoders · visual email designer for woocommerce · CWE-89 | Высокая8,8 | — | 0,9 % | 2 янв. 2023 г. |
35Наблюдать | CVE-2023-4140Эксплойта нет | WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalationsmackcoders · wp ultimate csv importer · CWE-269 | Высокая8,8 | — | 0,8 % | 3 авг. 2023 г. |
35Наблюдать | CVE-2018-20967Эксплойта нет | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-352 | Высокая8,8 | — | 0,6 % | 14 авг. 2019 г. |
35Наблюдать | CVE-2018-20968Эксплойта нет | The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.smackcoders · ultimate exporter · CWE-352 | Высокая8,8 | — | 0,6 % | 14 авг. 2019 г. |
35Наблюдать | CVE-2015-10125Эксплойта нет | WP Ultimate CSV Importer Plugin cross-site request forgerysmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-352 | Высокая8,8 | — | 0,4 % | 5 окт. 2023 г. |
30Наблюдать | CVE-2023-4139Эксплойта нет | WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listingsmackcoders · wp ultimate csv importer · CWE-200 | Высокая7,5 | — | 0,7 % | 3 авг. 2023 г. |
30Наблюдать | CVE-2023-45066Эксплойта нет | WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposuresmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-200 | Высокая7,5 | — | 0,5 % | 30 нояб. 2023 г. |
30Наблюдать | CVE-2024-12315Эксплойта нет | Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directorysmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-922 | Высокая7,5 | — | 0,5 % | 12 февр. 2025 г. |
30Наблюдать | CVE-2023-2487Эксплойта нет | WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposuresmackcoders · export all posts\, products\, orders\, refunds \& users · CWE-200 | Высокая7,5 | — | 0,5 % | 21 дек. 2023 г. |
28Наблюдать | CVE-2022-1977Эксплойта нет | WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRFsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-918 | Высокая7,2 | — | 1,3 % | 27 июн. 2022 г. |
28Наблюдать | CVE-2022-3243Эксплойта нет | Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLismackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-89 | Высокая7,2 | — | 1,1 % | 17 окт. 2022 г. |
26Наблюдать | CVE-2013-3264Эксплойта нет | The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2smackcoders · wp ultimate email marketer plugin · CWE-264 | Средняя6,4 | — | 2,1 % | 5 нояб. 2013 г. |
24Наблюдать | CVE-2016-10985Эксплойта нет | The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.smackcoders · echo sign · CWE-79 | Средняя6,1 | — | 1,4 % | 17 сент. 2019 г. |
24Наблюдать | CVE-2016-10984Эксплойта нет | The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.smackcoders · echo sign · CWE-79 | Средняя6,1 | — | 1,4 % | 17 сент. 2019 г. |
24Наблюдать | CVE-2015-9306Эксплойта нет | The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-79 | Средняя6,1 | — | 1,0 % | 12 авг. 2019 г. |
19Наблюдать | CVE-2022-0360Эксплойта нет | WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scriptingsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-79 | Средняя4,8 | — | 0,6 % | 28 февр. 2022 г. |
17Наблюдать | CVE-2013-3263Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow smackcoders · wp ultimate email marketer plugin · CWE-79 | Средняя4,3 | — | 1,6 % | 5 нояб. 2013 г. |
17Наблюдать | CVE-2024-9364Эксплойта нет | SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletionsmackcoders · sendgrid · CWE-862 | Средняя4,3 | — | 0,4 % | 18 окт. 2024 г. |
17Наблюдать | CVE-2025-5692Эксплойта нет | Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actionssmackcoders · lead form data collection to crm · CWE-862 | Средняя4,3 | — | 0,2 % | 1 июл. 2025 г. |
16Наблюдать | CVE-2022-3244Эксплойта нет | Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisationsmackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv · CWE-862 | Средняя4,2 | — | 0,4 % | 17 окт. 2022 г. |
- CVE-2016-1100040В плане
The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %smackcoders · ultimate exporter20 сент. 2019 г.
- CVE-2024-4396540В плане
WordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 2 %smackcoders · sendgrid29 авг. 2024 г.
- CVE-2023-414135Наблюдать
WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) PHP File Creation to Remote Code Execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %smackcoders · wp ultimate csv importer3 авг. 2023 г.
- CVE-2023-414235Наблюдать
WP Ultimate CSV Importer <= 7.9.8 - Authenticated (Author+) Remote Code Execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %smackcoders · wp ultimate csv importer3 авг. 2023 г.
- CVE-2022-386035Наблюдать
Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %smackcoders · visual email designer for woocommerce2 янв. 2023 г.
- CVE-2023-414035Наблюдать
WP Ultimate CSV Importer <= 7.9.8 - Arbitrary Usermeta Update to Authenticated (Author+) Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %smackcoders · wp ultimate csv importer3 авг. 2023 г.
- CVE-2018-2096735Наблюдать
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv14 авг. 2019 г.
- CVE-2018-2096835Наблюдать
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %smackcoders · ultimate exporter14 авг. 2019 г.
- CVE-2015-1012535Наблюдать
WP Ultimate CSV Importer Plugin cross-site request forgery
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv5 окт. 2023 г.
- CVE-2023-413930Наблюдать
WP Ultimate CSV Importer <= 7.9.8 - Sensitive Information Exposure via Directory Listing
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %smackcoders · wp ultimate csv importer3 авг. 2023 г.
- CVE-2023-4506630Наблюдать
WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %smackcoders · export all posts\, products\, orders\, refunds \& users30 нояб. 2023 г.
- CVE-2024-1231530Наблюдать
Export All Posts, Products, Orders, Refunds & Users <= 2.9.3 - Information Disclosure Through Unprotected Directory
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %smackcoders · export all posts\, products\, orders\, refunds \& users12 февр. 2025 г.
- CVE-2023-248730Наблюдать
WordPress WP Ultimate Exporter Plugin <= 2.4.1 is vulnerable to Sensitive Data Exposure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %smackcoders · export all posts\, products\, orders\, refunds \& users21 дек. 2023 г.
- CVE-2022-197728Наблюдать
WP Ultimate CSV Importer < 6.5.3 - Admin+ Blind SSRF
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv27 июн. 2022 г.
- CVE-2022-324328Наблюдать
Import all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLi
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 окт. 2022 г.
- CVE-2013-326426Наблюдать
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2
СредняяCVSS 6,4Эксплойта нетEPSS 2 %smackcoders · wp ultimate email marketer plugin5 нояб. 2013 г.
- CVE-2016-1098524Наблюдать
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %smackcoders · echo sign17 сент. 2019 г.
- CVE-2016-1098424Наблюдать
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %smackcoders · echo sign17 сент. 2019 г.
- CVE-2015-930624Наблюдать
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv12 авг. 2019 г.
- CVE-2022-036019Наблюдать
WP Ultimate CSV Importer < 6.4.3 - Admin+ Stored Cross-Site Scripting
СредняяCVSS 4,8Эксплойта нетEPSS 1 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv28 февр. 2022 г.
- CVE-2013-326317Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow
СредняяCVSS 4,3Эксплойта нетEPSS 2 %smackcoders · wp ultimate email marketer plugin5 нояб. 2013 г.
- CVE-2024-936417Наблюдать
SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
СредняяCVSS 4,3Эксплойта нетEPSS 0 %smackcoders · sendgrid18 окт. 2024 г.
- CVE-2025-569217Наблюдать
Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions
СредняяCVSS 4,3Эксплойта нетEPSS 0 %smackcoders · lead form data collection to crm1 июл. 2025 г.
- CVE-2022-324416Наблюдать
Import all XML, CSV & TXT into WordPress < 6.5.8 - Missing Authorisation
СредняяCVSS 4,2Эксплойта нетEPSS 0 %smackcoders · import all pages\, post types\, products\, orders\, and users as xml \& csv17 окт. 2022 г.