ISMAILSHADOW
15 kredili kayıt · son 12 ayda 10 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
28İzleyin | CVE-2026-2374İstismar yok | Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via PHP_SELFrobertpeake · login no captcha recaptcha · CWE-79 | Yüksek7,2 | — | %0,3 | 28 May 2026 |
32İzleyin | CVE-2026-4347İstismar yok | MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dirinc2734 · mw wp form · CWE-22 | Yüksek8,1 | — | %0,9 | 2 Nis 2026 |
40Planlayın | CVE-2026-3584Kavram kanıtı | Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_processwpchill · kali forms — contact form & drag-and-drop builder · CWE-94 | Kritik9,8 | — | %4,4 | 20 Mar 2026 |
26İzleyin | CVE-2025-14799İstismar yok | Brevo - Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Jugglingneeraj_slit · brevo – email, sms, web push, chat, and more. · CWE-843 | Orta6,5 | — | %0,5 | 18 Şub 2026 |
21İzleyin | CVE-2026-1927İstismar yok | GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cwpsoul · greenshift – animation and page builder blocks · CWE-862 | Orta5,4 | — | %0,2 | 5 Şub 2026 |
31İzleyin | CVE-2025-14437Kavram kanıtı | Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log Filewpmudev · hummingbird performance – cache & page speed optimization for core web vitals | critical css | minify css | defer css javascript | cdn · CWE-532 | Yüksek7,5 | — | %1,9 | 18 Ara 2025 |
28İzleyin | CVE-2025-13645İstismar yok | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletionwpchill · modula image gallery · CWE-22 | Yüksek7,2 | — | %1,0 | 2 Ara 2025 |
35İzleyin | CVE-2025-13536İstismar yok | Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'blubrry · powerpress podcasting plugin by blubrry · CWE-434 | Yüksek8,8 | — | %0,6 | 27 Kas 2025 |
28İzleyin | CVE-2025-12844İstismar yok | AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserializationtigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress · CWE-502 | Yüksek7,1 | — | %0,4 | 13 Kas 2025 |
35İzleyin | CVE-2025-9334İstismar yok | Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injectioncodesolz · better find and replace – ai-powered suggestions · CWE-94 | Yüksek8,8 | — | %0,5 | 8 Kas 2025 |
26İzleyin | CVE-2025-6189İstismar yok | Duplicate Page and Post <= 2.9.5 - Authenticated (Contributor+) SQL Injection via meta_key Parameterarjunthakur · duplicate page and post · CWE-89 | Orta6,5 | — | %0,3 | 10 Eyl 2025 |
26İzleyin | CVE-2025-8268İstismar yok | Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletiontigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress · CWE-862 | Orta6,5 | — | %0,3 | 3 Eyl 2025 |
35İzleyin | CVE-2025-7847Kavram kanıtı | AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Uploadtigroumeow · ai engine · CWE-434 | Yüksek8,8 | — | %1,1 | 31 Tem 2025 |
26İzleyin | CVE-2025-7780İstismar yok | AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functionstigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress · CWE-200 | Orta6,5 | — | %0,5 | 24 Tem 2025 |
25İzleyin | CVE-2025-7367İstismar yok | Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fieldswpchill · strong testimonials · CWE-79 | Orta6,4 | — | %0,2 | 15 Tem 2025 |
- CVE-2026-237428İzleyin
Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via PHP_SELF
YüksekCVSS 7,2İstismar yokEPSS %0robertpeake · login no captcha recaptcha28 May 2026
- CVE-2026-434732İzleyin
MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir
YüksekCVSS 8,1İstismar yokEPSS %1inc2734 · mw wp form2 Nis 2026
- CVE-2026-358440Planlayın
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
KritikCVSS 9,8Kavram kanıtıEPSS %4wpchill · kali forms — contact form & drag-and-drop builder20 Mar 2026
- CVE-2025-1479926İzleyin
Brevo - Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Juggling
OrtaCVSS 6,5İstismar yokEPSS %0neeraj_slit · brevo – email, sms, web push, chat, and more.18 Şub 2026
- CVE-2026-192721İzleyin
GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored C
OrtaCVSS 5,4İstismar yokEPSS %0wpsoul · greenshift – animation and page builder blocks5 Şub 2026
- CVE-2025-1443731İzleyin
Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
YüksekCVSS 7,5Kavram kanıtıEPSS %2wpmudev · hummingbird performance – cache & page speed optimization for core web vitals | critical css | minify css | defer css javascript | cdn18 Ara 2025
- CVE-2025-1364528İzleyin
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
YüksekCVSS 7,2İstismar yokEPSS %1wpchill · modula image gallery2 Ara 2025
- CVE-2025-1353635İzleyin
Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'
YüksekCVSS 8,8İstismar yokEPSS %1blubrry · powerpress podcasting plugin by blubrry27 Kas 2025
- CVE-2025-1284428İzleyin
AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization
YüksekCVSS 7,1İstismar yokEPSS %0tigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress13 Kas 2025
- CVE-2025-933435İzleyin
Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection
YüksekCVSS 8,8İstismar yokEPSS %1codesolz · better find and replace – ai-powered suggestions8 Kas 2025
- CVE-2025-618926İzleyin
Duplicate Page and Post <= 2.9.5 - Authenticated (Contributor+) SQL Injection via meta_key Parameter
OrtaCVSS 6,5İstismar yokEPSS %0arjunthakur · duplicate page and post10 Eyl 2025
- CVE-2025-826826İzleyin
Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion
OrtaCVSS 6,5İstismar yokEPSS %0tigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress3 Eyl 2025
- CVE-2025-784735İzleyin
AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload
YüksekCVSS 8,8Kavram kanıtıEPSS %1tigroumeow · ai engine31 Tem 2025
- CVE-2025-778026İzleyin
AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions
OrtaCVSS 6,5İstismar yokEPSS %1tigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress24 Tem 2025
- CVE-2025-736725İzleyin
Strong Testimonials <= 3.2.11 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields
OrtaCVSS 6,4İstismar yokEPSS %0wpchill · strong testimonials15 Tem 2025