Записи stellarwp
10 опубликованных записей вендора stellarwp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-287 Improper Authentication1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2024-8275Proof of concept | The Events Calendar <= 6.6.4 - Unauthenticated SQL Injectionstellarwp · the events calendar · CWE-89 | Критическая9,8 | — | 49,9 % | 25 сент. 2024 г. |
37Наблюдать | CVE-2024-4180Proof of concept | The Events Calendar < 6.4.0.1 - Reflected XSSstellarwp · the events calendar · CWE-79 | Критическая9,1 | — | 1,8 % | 4 июн. 2024 г. |
30Наблюдать | CVE-2023-6203Эксплойта нет | The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Readstellarwp · the events calendar · CWE-287 | Высокая7,5 | — | 0,8 % | 18 дек. 2023 г. |
29Наблюдать | CVE-2024-6931Эксплойта нет | The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scriptingstellarwp · the events calendar · CWE-79 | Средняя6,1 | — | 16,7 % | 27 сент. 2024 г. |
24Наблюдать | CVE-2019-15109Эксплойта нет | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.stellarwp · the events calendar · CWE-79 | Средняя6,1 | — | 1,1 % | 21 авг. 2019 г. |
21Наблюдать | CVE-2024-5333Proof of concept | The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosurestellarwp · the events calendar · CWE-639 | Средняя5,3 | — | 1,1 % | 16 дек. 2024 г. |
21Наблюдать | CVE-2023-6557Эксплойта нет | The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposurestellarwp · the events calendar · CWE-862 | Средняя5,3 | — | 0,6 % | 5 февр. 2024 г. |
21Наблюдать | CVE-2025-5144Эксплойта нет | The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingstellarwp · the events calendar · CWE-79 | Средняя5,4 | — | 0,3 % | 11 июн. 2025 г. |
19Наблюдать | CVE-2024-8493Эксплойта нет | The Events Calendar < 6.6.4 - Admin+ Stored XSSstellarwp · the events calendar · CWE-79 | Средняя4,8 | — | 0,3 % | 15 мая 2025 г. |
19Наблюдать | CVE-2024-10939Эксплойта нет | Image Widget < 4.4.11 - Admin+ Stored XSSstellarwp · image widget · CWE-79 | Средняя4,8 | — | 0,3 % | 13 дек. 2024 г. |
- CVE-2024-827554В плане
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 50 %stellarwp · the events calendar25 сент. 2024 г.
- CVE-2024-418037Наблюдать
The Events Calendar < 6.4.0.1 - Reflected XSS
КритическаяCVSS 9,1Proof of conceptEPSS 2 %stellarwp · the events calendar4 июн. 2024 г.
- CVE-2023-620330Наблюдать
The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %stellarwp · the events calendar18 дек. 2023 г.
- CVE-2024-693129Наблюдать
The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 17 %stellarwp · the events calendar27 сент. 2024 г.
- CVE-2019-1510924Наблюдать
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %stellarwp · the events calendar21 авг. 2019 г.
- CVE-2024-533321Наблюдать
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
СредняяCVSS 5,3Proof of conceptEPSS 1 %stellarwp · the events calendar16 дек. 2024 г.
- CVE-2023-655721Наблюдать
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 1 %stellarwp · the events calendar5 февр. 2024 г.
- CVE-2025-514421Наблюдать
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
СредняяCVSS 5,4Эксплойта нетEPSS 0 %stellarwp · the events calendar11 июн. 2025 г.
- CVE-2024-849319Наблюдать
The Events Calendar < 6.6.4 - Admin+ Stored XSS
СредняяCVSS 4,8Эксплойта нетEPSS 0 %stellarwp · the events calendar15 мая 2025 г.
- CVE-2024-1093919Наблюдать
Image Widget < 4.4.11 - Admin+ Stored XSS
СредняяCVSS 4,8Эксплойта нетEPSS 0 %stellarwp · image widget13 дек. 2024 г.