Записи wpsupportplus
9 опубликованных записей вендора wpsupportplus.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 11,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-20 Improper Input Validation1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-10389Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.wpsupportplus · wp support plus responsive ticket system · CWE-287 | Критическая9,8 | — | 2,2 % | 22 авг. 2019 г. |
40В плане | CVE-2018-1000131Эксплойта нет | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the functwpsupportplus · wp support plus responsive ticket system · CWE-89 | Критическая9,8 | — | 2,1 % | 14 мар. 2018 г. |
40В плане | CVE-2016-10930Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.wpsupportplus · wp support plus responsive ticket system · CWE-20 | Критическая9,8 | — | 2,0 % | 22 авг. 2019 г. |
40В плане | CVE-2014-10387Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.wpsupportplus · wp support plus responsive ticket system · CWE-89 | Критическая9,8 | — | 1,8 % | 22 авг. 2019 г. |
37Наблюдать | CVE-2014-10390Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.wpsupportplus · wp support plus responsive ticket system · CWE-22 | Критическая9,1 | — | 2,5 % | 22 авг. 2019 г. |
24Наблюдать | CVE-2019-7299Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1wpsupportplus · wp support plus responsive ticket system · CWE-79 | Средняя6,1 | — | 1,7 % | 21 мар. 2019 г. |
24Наблюдать | CVE-2014-10391Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.wpsupportplus · wp support plus responsive ticket system · CWE-74 | Средняя6,1 | — | 0,9 % | 22 авг. 2019 г. |
24Наблюдать | CVE-2019-15331Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.wpsupportplus · wp support plus responsive ticket system · CWE-79 | Средняя6,1 | — | 0,9 % | 22 авг. 2019 г. |
21Наблюдать | CVE-2014-10388Эксплойта нет | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.wpsupportplus · wp support plus responsive ticket system · CWE-200 | Средняя5,3 | — | 1,3 % | 22 авг. 2019 г. |
- CVE-2014-1038940В плане
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.
- CVE-2018-100013140В плане
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the funct
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wpsupportplus · wp support plus responsive ticket system14 мар. 2018 г.
- CVE-2016-1093040В плане
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.
- CVE-2014-1038740В плане
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.
- CVE-2014-1039037Наблюдать
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.
- CVE-2019-729924Наблюдать
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1
СредняяCVSS 6,1Эксплойта нетEPSS 2 %wpsupportplus · wp support plus responsive ticket system21 мар. 2019 г.
- CVE-2014-1039124Наблюдать
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.
- CVE-2019-1533124Наблюдать
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.
- CVE-2014-1038821Наблюдать
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %wpsupportplus · wp support plus responsive ticket system22 авг. 2019 г.