Deadbee
16 kredili kayıt · son 12 ayda 16 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
17İzleyin | CVE-2026-5582İstismar yok | FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Togglefusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.) · CWE-352 | Orta4,3 | — | %0,2 | 30 Tem 2026 |
25İzleyin | CVE-2026-0736İstismar yok | Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Fieldcollectchat · chatbot for wordpress by collect.chat ⚡️ · CWE-79 | Orta6,4 | — | %0,3 | 14 Şub 2026 |
28İzleyin | CVE-2026-1320İstismar yok | Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Headerays-pro · secure copy content protection and content locking · CWE-79 | Yüksek7,2 | — | %0,3 | 12 Şub 2026 |
21İzleyin | CVE-2025-15510İstismar yok | NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposurewebaways · nex-forms – ultimate forms plugin for wordpress · CWE-862 | Orta5,3 | — | %0,3 | 30 Oca 2026 |
29İzleyin | CVE-2026-0832İstismar yok | New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosuresaadiqbal · new user approve · CWE-862 | Yüksek7,3 | — | %0,4 | 28 Oca 2026 |
24İzleyin | CVE-2025-14375İstismar yok | RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via classNamerebelcode · rss aggregator – rss import, news feeds, feed to post, and autoblogging · CWE-79 | Orta6,1 | — | %0,2 | 16 Oca 2026 |
21İzleyin | CVE-2025-14507İstismar yok | EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST APImetagauss · eventprime – events calendar, bookings and tickets · CWE-200 | Orta5,3 | — | %0,4 | 13 Oca 2026 |
21İzleyin | CVE-2025-14043İstismar yok | Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creationtainacan · tainacan · CWE-862 | Orta5,3 | — | %0,3 | 20 Ara 2025 |
17İzleyin | CVE-2025-14277İstismar yok | Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgerybdthemes · prime slider – addons for elementor · CWE-918 | Orta4,3 | — | %0,3 | 18 Ara 2025 |
21İzleyin | CVE-2025-14442İstismar yok | Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export Fileays-pro · secure copy content protection and content locking · CWE-552 | Orta5,3 | — | %0,3 | 12 Ara 2025 |
17İzleyin | CVE-2025-14159İstismar yok | Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Exportays-pro · secure copy content protection and content locking · CWE-352 | Orta4,3 | — | %0,2 | 12 Ara 2025 |
21İzleyin | CVE-2025-13006İstismar yok | SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposurewpeka-club · surveyfunnel – survey plugin for wordpress · CWE-200 | Orta5,3 | — | %0,3 | 5 Ara 2025 |
17İzleyin | CVE-2025-13685İstismar yok | Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actionsays-pro · photo gallery by ays – responsive image gallery · CWE-352 | Orta4,3 | — | %0,2 | 2 Ara 2025 |
17İzleyin | CVE-2025-13143İstismar yok | Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnectionassafp · quiz, poll & survey maker by opinion stage · CWE-352 | Orta4,3 | — | %0,2 | 27 Kas 2025 |
21İzleyin | CVE-2025-12747İstismar yok | Tainacan <= 1.0.0 - Unauthenticated Information Exposuretainacan · tainacan · CWE-552 | Orta5,3 | — | %0,3 | 21 Kas 2025 |
24İzleyin | CVE-2025-12746İstismar yok | Tainacan <= 1.0.0 - Reflected Cross-Site Scriptingtainacan · tainacan · CWE-79 | Orta6,1 | — | %0,3 | 21 Kas 2025 |
- CVE-2026-558217İzleyin
FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle
OrtaCVSS 4,3İstismar yokEPSS %0fusewp · fusewp – wordpress user sync to email list & marketing automation (mailchimp, constant contact, activecampaign etc.)30 Tem 2026
- CVE-2026-073625İzleyin
Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field
OrtaCVSS 6,4İstismar yokEPSS %0collectchat · chatbot for wordpress by collect.chat ⚡️14 Şub 2026
- CVE-2026-132028İzleyin
Secure Copy Content Protection and Content Locking <= 4.9.8 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
YüksekCVSS 7,2İstismar yokEPSS %0ays-pro · secure copy content protection and content locking12 Şub 2026
- CVE-2025-1551021İzleyin
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %0webaways · nex-forms – ultimate forms plugin for wordpress30 Oca 2026
- CVE-2026-083229İzleyin
New User Approve <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure
YüksekCVSS 7,3İstismar yokEPSS %0saadiqbal · new user approve28 Oca 2026
- CVE-2025-1437524İzleyin
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className
OrtaCVSS 6,1İstismar yokEPSS %0rebelcode · rss aggregator – rss import, news feeds, feed to post, and autoblogging16 Oca 2026
- CVE-2025-1450721İzleyin
EventPrime - Events Calendar, Bookings and Tickets <= 4.2.7.0 - Unauthenticated Sensitive Information Exposure via REST API
OrtaCVSS 5,3İstismar yokEPSS %0metagauss · eventprime – events calendar, bookings and tickets13 Oca 2026
- CVE-2025-1404321İzleyin
Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation
OrtaCVSS 5,3İstismar yokEPSS %0tainacan · tainacan20 Ara 2025
- CVE-2025-1427717İzleyin
Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery
OrtaCVSS 4,3İstismar yokEPSS %0bdthemes · prime slider – addons for elementor18 Ara 2025
- CVE-2025-1444221İzleyin
Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File
OrtaCVSS 5,3İstismar yokEPSS %0ays-pro · secure copy content protection and content locking12 Ara 2025
- CVE-2025-1415917İzleyin
Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export
OrtaCVSS 4,3İstismar yokEPSS %0ays-pro · secure copy content protection and content locking12 Ara 2025
- CVE-2025-1300621İzleyin
SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %0wpeka-club · surveyfunnel – survey plugin for wordpress5 Ara 2025
- CVE-2025-1368517İzleyin
Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions
OrtaCVSS 4,3İstismar yokEPSS %0ays-pro · photo gallery by ays – responsive image gallery2 Ara 2025
- CVE-2025-1314317İzleyin
Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection
OrtaCVSS 4,3İstismar yokEPSS %0assafp · quiz, poll & survey maker by opinion stage27 Kas 2025
- CVE-2025-1274721İzleyin
Tainacan <= 1.0.0 - Unauthenticated Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %0tainacan · tainacan21 Kas 2025
- CVE-2025-1274624İzleyin
Tainacan <= 1.0.0 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0tainacan · tainacan21 Kas 2025