Записи tinymce
7 опубликованных записей вендора tinymce.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 14,3 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 42,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2011-4825Готовый эксплойт | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phptinymce · tinymce · CWE-94 | Высокая7,5 | — | 39,2 % | 14 дек. 2011 г. |
27Наблюдать | CVE-2014-3845Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijactinymce · color picker · CWE-352 | Средняя6,8 | — | 1,0 % | 22 мая 2014 г. |
21Наблюдать | CVE-2012-6112Эксплойта нет | classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2tinymce · spellchecker php · CWE-264 | Средняя5,0 | — | 2,3 % | 27 янв. 2013 г. |
21Наблюдать | CVE-2014-3844Эксплойта нет | The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugintinymce · color picker · CWE-264 | Средняя5,0 | — | 1,8 % | 22 мая 2014 г. |
20Наблюдать | CVE-2012-3414Proof of concept | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Imagetinymce · image manager · CWE-79 | Средняя4,3 | — | 9,1 % | 19 июл. 2013 г. |
18Наблюдать | CVE-2013-2204Эксплойта нет | moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not considertinymce · media · CWE-20 | Средняя4,3 | — | 2,9 % | 8 июл. 2013 г. |
17Наблюдать | CVE-2012-4230Эксплойта нет | The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elementinymce · tinymce · CWE-264 | Средняя4,3 | — | 1,2 % | 25 апр. 2014 г. |
- CVE-2011-482542В плане
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, php
ВысокаяCVSS 7,5Готовый эксплойтEPSS 39 %tinymce · tinymce14 дек. 2011 г.
- CVE-2014-384527Наблюдать
Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijac
СредняяCVSS 6,8Эксплойта нетEPSS 1 %tinymce · color picker22 мая 2014 г.
- CVE-2012-611221Наблюдать
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2
СредняяCVSS 5,0Эксплойта нетEPSS 2 %tinymce · spellchecker php27 янв. 2013 г.
- CVE-2014-384421Наблюдать
The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin
СредняяCVSS 5,0Эксплойта нетEPSS 2 %tinymce · color picker22 мая 2014 г.
- CVE-2012-341420Наблюдать
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image
СредняяCVSS 4,3Proof of conceptEPSS 9 %tinymce · image manager19 июл. 2013 г.
- CVE-2013-220418Наблюдать
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider
СредняяCVSS 4,3Эксплойта нетEPSS 3 %tinymce · media8 июл. 2013 г.
- CVE-2012-423017Наблюдать
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elemen
СредняяCVSS 4,3Эксплойта нетEPSS 1 %tinymce · tinymce25 апр. 2014 г.