Записи websitebaker
16 опубликованных записей вендора websitebaker.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-306 Missing Authentication for Critical Function1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-7410Proof of concept | Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackewebsitebaker · websitebaker · CWE-89 | Критическая9,8 | — | 2,9 % | 3 апр. 2017 г. |
40В плане | CVE-2020-25990Эксплойта нет | WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php.websitebaker · websitebaker · CWE-89 | Критическая9,8 | — | 1,7 % | 1 окт. 2020 г. |
39Наблюдать | CVE-2017-9771Эксплойта нет | install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or websitebaker · websitebaker · CWE-94 | Критическая9,8 | — | 1,4 % | 21 июн. 2017 г. |
39Наблюдать | CVE-2017-9360Эксплойта нет | WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.websitebaker · websitebaker · CWE-89 | Критическая9,8 | — | 1,0 % | 2 июн. 2017 г. |
35Наблюдать | CVE-2011-2934Эксплойта нет | A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate websitebaker · websitebaker · CWE-352 | Высокая8,8 | — | 0,5 % | 14 янв. 2020 г. |
34Наблюдать | CVE-2021-47788Эксплойта нет | WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)websitebaker · websitebaker · CWE-434 | Высокая8,7 | — | 1,0 % | 15 янв. 2026 г. |
31Наблюдать | CVE-2014-9242Proof of concept | SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via thwebsitebaker · websitebaker · CWE-89 | Высокая7,5 | — | 2,1 % | 3 дек. 2014 г. |
30Наблюдать | CVE-2011-4322Эксплойта нет | websitebaker prior to and including 2.8.1 has an authentication error in backup module.websitebaker · websitebaker · CWE-306 | Высокая7,5 | — | 1,2 % | 21 янв. 2020 г. |
28Наблюдать | CVE-2011-2933Эксплойта нет | An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploawebsitebaker · websitebaker · CWE-434 | Высокая7,2 | — | 1,1 % | 14 янв. 2020 г. |
28Наблюдать | CVE-2023-53902Эксплойта нет | WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpointwebsitebaker · websitebaker · CWE-22 | Высокая7,0 | — | 1,0 % | 16 дек. 2025 г. |
24Наблюдать | CVE-2017-16514Эксплойта нет | Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /websitebaker · websitebaker · CWE-79 | Средняя6,1 | — | 0,6 % | 10 янв. 2018 г. |
24Наблюдать | CVE-2017-9361Эксплойта нет | WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.websitebaker · websitebaker · CWE-79 | Средняя6,1 | — | 0,6 % | 2 июн. 2017 г. |
20Наблюдать | CVE-2023-53903Эксплойта нет | WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Uploadwebsitebaker · websitebaker · CWE-79 | Средняя5,1 | — | 0,2 % | 16 дек. 2025 г. |
20Наблюдать | CVE-2023-53953Эксплойта нет | WebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creationwebsitebaker · websitebaker · CWE-79 | Средняя5,1 | — | 0,2 % | 19 дек. 2025 г. |
18Наблюдать | CVE-2014-9243Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via websitebaker · websitebaker · CWE-79 | Средняя4,3 | — | 2,5 % | 3 дек. 2014 г. |
18Наблюдать | CVE-2015-0553Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary webwebsitebaker · websitebaker · CWE-79 | Средняя4,3 | — | 2,0 % | 21 янв. 2015 г. |
- CVE-2017-741040В плане
Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attacke
КритическаяCVSS 9,8Proof of conceptEPSS 3 %websitebaker · websitebaker3 апр. 2017 г.
- CVE-2020-2599040В плане
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %websitebaker · websitebaker1 окт. 2020 г.
- CVE-2017-977139Наблюдать
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %websitebaker · websitebaker21 июн. 2017 г.
- CVE-2017-936039Наблюдать
WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %websitebaker · websitebaker2 июн. 2017 г.
- CVE-2011-293435Наблюдать
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %websitebaker · websitebaker14 янв. 2020 г.
- CVE-2021-4778834Наблюдать
WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %websitebaker · websitebaker15 янв. 2026 г.
- CVE-2014-924231Наблюдать
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via th
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %websitebaker · websitebaker3 дек. 2014 г.
- CVE-2011-432230Наблюдать
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %websitebaker · websitebaker21 янв. 2020 г.
- CVE-2011-293328Наблюдать
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploa
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %websitebaker · websitebaker14 янв. 2020 г.
- CVE-2023-5390228Наблюдать
WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %websitebaker · websitebaker16 дек. 2025 г.
- CVE-2017-1651424Наблюдать
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /
СредняяCVSS 6,1Эксплойта нетEPSS 1 %websitebaker · websitebaker10 янв. 2018 г.
- CVE-2017-936124Наблюдать
WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %websitebaker · websitebaker2 июн. 2017 г.
- CVE-2023-5390320Наблюдать
WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Upload
СредняяCVSS 5,1Эксплойта нетEPSS 0 %websitebaker · websitebaker16 дек. 2025 г.
- CVE-2023-5395320Наблюдать
WebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creation
СредняяCVSS 5,1Эксплойта нетEPSS 0 %websitebaker · websitebaker19 дек. 2025 г.
- CVE-2014-924318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Proof of conceptEPSS 2 %websitebaker · websitebaker3 дек. 2014 г.
- CVE-2015-055318Наблюдать
Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Эксплойта нетEPSS 2 %websitebaker · websitebaker21 янв. 2015 г.