Записи Webcraftic
6 опубликованных записей вендора webcraftic.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-306 Missing Authentication for Critical Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-15858Proof of concept | admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, webcraftic · woody ad snippets · CWE-306 | Высокая8,8 | — | 18,5 % | 3 сент. 2019 г. |
40В плане | CVE-2024-3105Proof of concept | Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Executionthemeisle · woody code snippets – insert php, css, js, and header/footer scripts · CWE-94 | Критическая9,9 | — | 2,8 % | 15 июн. 2024 г. |
30Наблюдать | CVE-2019-14773Эксплойта нет | admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?actionwebcraftic · woody ad snippets | Высокая7,5 | — | 1,6 % | 8 авг. 2019 г. |
24Наблюдать | CVE-2019-15818Эксплойта нет | The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301expowebcraftic · simple 301 redirects · CWE-601 | Средняя6,1 | — | 1,5 % | 30 авг. 2019 г. |
24Наблюдать | CVE-2019-15776Эксплойта нет | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a Cwebcraftic · simple 301 redirects-addon-bulk uploader · CWE-601 | Средняя6,1 | — | 1,3 % | 29 авг. 2019 г. |
21Наблюдать | CVE-2019-16289Эксплойта нет | The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.webcraftic · woody ad snippets · CWE-79 | Средняя5,4 | — | 1,0 % | 13 сент. 2019 г. |
- CVE-2019-1585841В плане
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import,
ВысокаяCVSS 8,8Proof of conceptEPSS 18 %webcraftic · woody ad snippets3 сент. 2019 г.
- CVE-2024-310540В плане
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
КритическаяCVSS 9,9Proof of conceptEPSS 3 %themeisle · woody code snippets – insert php, css, js, and header/footer scripts15 июн. 2024 г.
- CVE-2019-1477330Наблюдать
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %webcraftic · woody ad snippets8 авг. 2019 г.
- CVE-2019-1581824Наблюдать
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301expo
СредняяCVSS 6,1Эксплойта нетEPSS 1 %webcraftic · simple 301 redirects30 авг. 2019 г.
- CVE-2019-1577624Наблюдать
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a C
СредняяCVSS 6,1Эксплойта нетEPSS 1 %webcraftic · simple 301 redirects-addon-bulk uploader29 авг. 2019 г.
- CVE-2019-1628921Наблюдать
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %webcraftic · woody ad snippets13 сент. 2019 г.