Записи wpdevart
41 опубликованных записей вендора wpdevart.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 31,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-862 Missing Authorization4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-472 External Control of Assumed-Immutable Web Parameter1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
41 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2021-24442Proof of concept | Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injectionwpdevart · poll\, survey\, questionnaire and voting system · CWE-89 | Критическая9,8 | — | 46,0 % | 12 июл. 2021 г. |
40В плане | CVE-2022-3982Proof of concept | Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Uploadwpdevart · booking calendar · CWE-434 | Критическая9,8 | — | 4,5 % | 12 дек. 2022 г. |
40В плане | CVE-2017-14125Эксплойта нет | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary Swpdevart · responsive image gallery gallery album · CWE-89 | Критическая9,8 | — | 3,2 % | 25 сент. 2017 г. |
39Наблюдать | CVE-2022-47428Эксплойта нет | WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injectionwpdevart · booking calendar · CWE-89 | Критическая9,8 | — | 0,7 % | 6 нояб. 2023 г. |
39Наблюдать | CVE-2023-24373Эксплойта нет | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerabilitywpdevart · booking calendar · CWE-472 | Критическая9,8 | — | 0,4 % | 3 июн. 2024 г. |
35Наблюдать | CVE-2021-34636Эксплойта нет | Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site Scriptingwpdevart · countdown and countup\, woocommerce sales timer · CWE-352 | Высокая8,8 | — | 0,6 % | 28 сент. 2021 г. |
35Наблюдать | CVE-2023-24407Эксплойта нет | WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerabilitywpdevart · booking calendar · CWE-862 | Высокая8,8 | — | 0,5 % | 9 дек. 2024 г. |
35Наблюдать | CVE-2024-35750Эксплойта нет | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerabilitywpdevart · gallery · CWE-89 | Высокая8,8 | — | 0,4 % | 8 июн. 2024 г. |
35Наблюдать | CVE-2023-24384Эксплойта нет | WordPress Organization chart Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF)wpdevart · organization chart · CWE-352 | Высокая8,8 | — | 0,3 % | 23 февр. 2023 г. |
35Наблюдать | CVE-2023-45629Эксплойта нет | WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)wpdevart · gallery - image and video gallery with thumbnails · CWE-352 | Высокая8,8 | — | 0,2 % | 16 окт. 2023 г. |
30Наблюдать | CVE-2018-10363Эксплойта нет | An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress.wpdevart · booking calendar · CWE-20 | Высокая7,5 | — | 1,4 % | 13 июн. 2018 г. |
29Наблюдать | CVE-2023-0900Proof of concept | AP Pricing Tables Lite <= 1.1.6 - Admin+ SQLiwpdevart · pricing table builder · CWE-89 | Высокая7,2 | — | 3,2 % | 5 июн. 2023 г. |
28Наблюдать | CVE-2024-9504Эксплойта нет | Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Uploadwpdevart · booking calendar, appointment booking system · CWE-434 | Высокая7,2 | — | 0,5 % | 26 нояб. 2024 г. |
26Наблюдать | CVE-2024-10856Эксплойта нет | Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injectionwpdevart · booking calendar · CWE-89 | Средняя6,5 | — | 0,5 % | 24 дек. 2024 г. |
25Наблюдать | CVE-2022-1946Proof of concept | Gallery < 2.0.0 - Reflected Cross-Site Scriptingwpdevart · gallery · CWE-79 | Средняя6,1 | — | 1,8 % | 4 июл. 2022 г. |
25Наблюдать | CVE-2024-37542Эксплойта нет | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerabilitywpdevart · gallery · CWE-862 | Средняя6,3 | — | 0,2 % | 6 июл. 2024 г. |
24Наблюдать | CVE-2022-0640Эксплойта нет | AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scriptingwpdevart · pricing table builder · CWE-79 | Средняя6,1 | — | 0,9 % | 21 мар. 2022 г. |
24Наблюдать | CVE-2022-47603Эксплойта нет | WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)wpdevart · image and video gallery with thumbnails · CWE-79 | Средняя6,1 | — | 0,4 % | 29 мар. 2023 г. |
24Наблюдать | CVE-2024-30550Эксплойта нет | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerabilitywpdevart · gallery · CWE-79 | Средняя6,1 | — | 0,4 % | 31 мар. 2024 г. |
24Наблюдать | CVE-2023-46075Эксплойта нет | WordPress Contact Form Builder, Contact Widget Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)wpdevart · contact form builder · CWE-79 | Средняя6,1 | — | 0,3 % | 26 окт. 2023 г. |
24Наблюдать | CVE-2023-45630Эксплойта нет | WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)wpdevart · gallery · CWE-79 | Средняя6,1 | — | 0,3 % | 18 окт. 2023 г. |
21Наблюдать | CVE-2021-24464Эксплойта нет | YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSSwpdevart · youtube embed\, playlist and popup · CWE-79 | Средняя5,4 | — | 0,6 % | 2 авг. 2021 г. |
21Наблюдать | CVE-2021-24577Эксплойта нет | Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSSwpdevart · coming soon and maintenance mode · CWE-79 | Средняя5,4 | — | 0,6 % | 11 окт. 2021 г. |
21Наблюдать | CVE-2023-0177Эксплойта нет | Social Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSSwpdevart · social like box and page · CWE-79 | Средняя5,4 | — | 0,5 % | 13 февр. 2023 г. |
21Наблюдать | CVE-2024-31120Эксплойта нет | WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerabilitywpdevart · gallery · CWE-79 | Средняя5,4 | — | 0,4 % | 31 мар. 2024 г. |
- CVE-2021-2444253В плане
Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 46 %wpdevart · poll\, survey\, questionnaire and voting system12 июл. 2021 г.
- CVE-2022-398240В плане
Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Proof of conceptEPSS 5 %wpdevart · booking calendar12 дек. 2022 г.
- CVE-2017-1412540В плане
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary S
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wpdevart · responsive image gallery gallery album25 сент. 2017 г.
- CVE-2022-4742839Наблюдать
WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.7 is vulnerable to SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wpdevart · booking calendar6 нояб. 2023 г.
- CVE-2023-2437339Наблюдать
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Bypass vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %wpdevart · booking calendar3 июн. 2024 г.
- CVE-2021-3463635Наблюдать
Countdown and CountUp, WooCommerce Sales Timer <= 1.5.7 Cross-Site Request Forgery to Stored Cross-Site Scripting
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpdevart · countdown and countup\, woocommerce sales timer28 сент. 2021 г.
- CVE-2023-2440735Наблюдать
WordPress Booking calendar, Appointment Booking System plugin <= 3.2.3 - Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wpdevart · booking calendar9 дек. 2024 г.
- CVE-2024-3575035Наблюдать
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpdevart · gallery8 июн. 2024 г.
- CVE-2023-2438435Наблюдать
WordPress Organization chart Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpdevart · organization chart23 февр. 2023 г.
- CVE-2023-4562935Наблюдать
WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wpdevart · gallery - image and video gallery with thumbnails16 окт. 2023 г.
- CVE-2018-1036330Наблюдать
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %wpdevart · booking calendar13 июн. 2018 г.
- CVE-2023-090029Наблюдать
AP Pricing Tables Lite <= 1.1.6 - Admin+ SQLi
ВысокаяCVSS 7,2Proof of conceptEPSS 3 %wpdevart · pricing table builder5 июн. 2023 г.
- CVE-2024-950428Наблюдать
Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %wpdevart · booking calendar, appointment booking system26 нояб. 2024 г.
- CVE-2024-1085626Наблюдать
Booking Calendar WpDevArt <= 3.2.19 - Authenticated (Contributor+) SQL Injection
СредняяCVSS 6,5Эксплойта нетEPSS 0 %wpdevart · booking calendar24 дек. 2024 г.
- CVE-2022-194625Наблюдать
Gallery < 2.0.0 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Proof of conceptEPSS 2 %wpdevart · gallery4 июл. 2022 г.
- CVE-2024-3754225Наблюдать
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control vulnerability
СредняяCVSS 6,3Эксплойта нетEPSS 0 %wpdevart · gallery6 июл. 2024 г.
- CVE-2022-064024Наблюдать
AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wpdevart · pricing table builder21 мар. 2022 г.
- CVE-2022-4760324Наблюдать
WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wpdevart · image and video gallery with thumbnails29 мар. 2023 г.
- CVE-2024-3055024Наблюдать
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wpdevart · gallery31 мар. 2024 г.
- CVE-2023-4607524Наблюдать
WordPress Contact Form Builder, Contact Widget Plugin <= 2.1.6 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wpdevart · contact form builder26 окт. 2023 г.
- CVE-2023-4563024Наблюдать
WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
СредняяCVSS 6,1Эксплойта нетEPSS 0 %wpdevart · gallery18 окт. 2023 г.
- CVE-2021-2446421Наблюдать
YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpdevart · youtube embed\, playlist and popup2 авг. 2021 г.
- CVE-2021-2457721Наблюдать
Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 1 %wpdevart · coming soon and maintenance mode11 окт. 2021 г.
- CVE-2023-017721Наблюдать
Social Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSS
СредняяCVSS 5,4Эксплойта нетEPSS 0 %wpdevart · social like box and page13 февр. 2023 г.
- CVE-2024-3112021Наблюдать
WordPress Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability
СредняяCVSS 5,4Эксплойта нетEPSS 0 %wpdevart · gallery31 мар. 2024 г.