Записи UpdraftPlus
19 опубликованных записей вендора updraftplus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 10,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2017-16871Эксплойта нет | The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plupdraftplus · updraftplus · CWE-94 | Высокая8,1 | — | 1,6 % | 17 нояб. 2017 г. |
32Наблюдать | CVE-2017-16870Эксплойта нет | The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.updraftplus · updraftplus · CWE-918 | Высокая8,1 | — | 1,0 % | 17 нояб. 2017 г. |
29Наблюдать | CVE-2023-0157Proof of concept | All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSSupdraftplus · all-in-one security · CWE-79 | Средняя4,8 | — | 32,5 % | 10 апр. 2023 г. |
27Наблюдать | CVE-2022-0633Эксплойта нет | UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Downloadupdraftplus · updraftplus · CWE-863 | Средняя6,5 | — | 2,1 % | 17 февр. 2022 г. |
26Наблюдать | CVE-2022-0864Proof of concept | UpdraftPlus < 1.22.9 - Reflected Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Средняя6,1 | — | 7,4 % | 4 апр. 2022 г. |
25Наблюдать | CVE-2023-0156Proof of concept | All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversalupdraftplus · all-in-one security · CWE-22 | Средняя4,9 | — | 19,9 % | 10 апр. 2023 г. |
24Наблюдать | CVE-2023-1119Proof of concept | Multiple Plugins - Cross-Site Scripting From Third-party Librarysrbtranslatin project · srbtranslatin · CWE-79 | Средняя6,1 | — | 1,2 % | 10 июл. 2023 г. |
24Наблюдать | CVE-2021-25022Эксплойта нет | UpdraftPlus < 1.16.66 - Reflected Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Средняя6,1 | — | 1,1 % | 3 янв. 2022 г. |
24Наблюдать | CVE-2015-9360Эксплойта нет | The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().updraftplus · updraftplus · CWE-79 | Средняя6,1 | — | 1,0 % | 28 авг. 2019 г. |
24Наблюдать | CVE-2017-18593Эксплойта нет | The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.updraftplus · updraftplus · CWE-79 | Средняя6,1 | — | 0,9 % | 28 авг. 2019 г. |
24Наблюдать | CVE-2021-25089Эксплойта нет | UpdraftPlus < 1.16.69 - Reflected Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Средняя6,1 | — | 0,8 % | 1 февр. 2022 г. |
24Наблюдать | CVE-2024-1037Эксплойта нет | All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scriptingupdraftplus · all-in-one security · CWE-79 | Средняя6,1 | — | 0,6 % | 7 февр. 2024 г. |
24Наблюдать | CVE-2023-26530Эксплойта нет | WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)updraftplus · updraft · CWE-79 | Средняя6,1 | — | 0,4 % | 17 авг. 2023 г. |
24Наблюдать | CVE-2023-32960Эксплойта нет | WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)updraftplus · updraftplus · CWE-352 | Средняя6,1 | — | 0,2 % | 22 июн. 2023 г. |
21Наблюдать | CVE-2022-4346Эксплойта нет | All In One WP Security & Firewall < 5.1.3 - Configuration Leakupdraftplus · all-in-one security · CWE-552 | Средняя5,3 | — | 0,7 % | 23 янв. 2023 г. |
21Наблюдать | CVE-2022-4097Эксплойта нет | All In One WP Security & Firewall < 5.0.8 - IP Spoofingupdraftplus · all-in-one security · CWE-639 | Средняя5,3 | — | 0,6 % | 12 дек. 2022 г. |
21Наблюдать | CVE-2023-5982Эксплойта нет | UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Updateupdraftplus · updraftplus · CWE-352 | Средняя5,4 | — | 0,2 % | 7 нояб. 2023 г. |
19Наблюдать | CVE-2021-24423Эксплойта нет | UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Средняя4,8 | — | 0,6 % | 24 янв. 2022 г. |
16Наблюдать | CVE-2025-3951Эксплойта нет | WP-Optimize < 4.2.0 - Admin+ SQLiupdraftplus · wp-optimize · CWE-89 | Средняя4,1 | — | 0,3 % | 2 июн. 2025 г. |
- CVE-2017-1687132Наблюдать
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/pl
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %updraftplus · updraftplus17 нояб. 2017 г.
- CVE-2017-1687032Наблюдать
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %updraftplus · updraftplus17 нояб. 2017 г.
- CVE-2023-015729Наблюдать
All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS
СредняяCVSS 4,8Proof of conceptEPSS 32 %updraftplus · all-in-one security10 апр. 2023 г.
- CVE-2022-063327Наблюдать
UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download
СредняяCVSS 6,5Эксплойта нетEPSS 2 %updraftplus · updraftplus17 февр. 2022 г.
- CVE-2022-086426Наблюдать
UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Proof of conceptEPSS 7 %updraftplus · updraftplus4 апр. 2022 г.
- CVE-2023-015625Наблюдать
All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal
СредняяCVSS 4,9Proof of conceptEPSS 20 %updraftplus · all-in-one security10 апр. 2023 г.
- CVE-2023-111924Наблюдать
Multiple Plugins - Cross-Site Scripting From Third-party Library
СредняяCVSS 6,1Proof of conceptEPSS 1 %srbtranslatin project · srbtranslatin10 июл. 2023 г.
- CVE-2021-2502224Наблюдать
UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %updraftplus · updraftplus3 янв. 2022 г.
- CVE-2015-936024Наблюдать
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
СредняяCVSS 6,1Эксплойта нетEPSS 1 %updraftplus · updraftplus28 авг. 2019 г.
- CVE-2017-1859324Наблюдать
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %updraftplus · updraftplus28 авг. 2019 г.
- CVE-2021-2508924Наблюдать
UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %updraftplus · updraftplus1 февр. 2022 г.
- CVE-2024-103724Наблюдать
All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %updraftplus · all-in-one security7 февр. 2024 г.
- CVE-2023-2653024Наблюдать
WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %updraftplus · updraft17 авг. 2023 г.
- CVE-2023-3296024Наблюдать
WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %updraftplus · updraftplus22 июн. 2023 г.
- CVE-2022-434621Наблюдать
All In One WP Security & Firewall < 5.1.3 - Configuration Leak
СредняяCVSS 5,3Эксплойта нетEPSS 1 %updraftplus · all-in-one security23 янв. 2023 г.
- CVE-2022-409721Наблюдать
All In One WP Security & Firewall < 5.0.8 - IP Spoofing
СредняяCVSS 5,3Эксплойта нетEPSS 1 %updraftplus · all-in-one security12 дек. 2022 г.
- CVE-2023-598221Наблюдать
UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update
СредняяCVSS 5,4Эксплойта нетEPSS 0 %updraftplus · updraftplus7 нояб. 2023 г.
- CVE-2021-2442319Наблюдать
UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting
СредняяCVSS 4,8Эксплойта нетEPSS 1 %updraftplus · updraftplus24 янв. 2022 г.
- CVE-2025-395116Наблюдать
WP-Optimize < 4.2.0 - Admin+ SQLi
СредняяCVSS 4,1Эксплойта нетEPSS 0 %updraftplus · wp-optimize2 июн. 2025 г.