Webula
Patchstack Bug Bounty Program
16 kredili kayıt · son 12 ayda 0 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
23İzleyin | CVE-2025-32135İstismar yok | WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerabilityrocketelements · split test for elementor · CWE-79 | Orta5,9 | — | %0,4 | 4 Nis 2025 |
23İzleyin | CVE-2025-31864Kavram kanıtı | WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerabilityout the box · beam me up scotty · CWE-79 | Orta5,9 | — | %0,3 | 1 Nis 2025 |
35İzleyin | CVE-2025-22783Kavram kanıtı | WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerabilitysquirrly · seo plugin by squirrly seo · CWE-89 | Yüksek8,8 | — | %0,6 | 27 Mar 2025 |
30İzleyin | CVE-2025-22652Kavram kanıtı | WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerabilitykendysond · payment forms for paystack · CWE-89 | Yüksek7,6 | — | %0,9 | 27 Mar 2025 |
30İzleyin | CVE-2025-30921Kavram kanıtı | WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerabilitytribulant software · newsletters · CWE-89 | Yüksek7,6 | — | %0,5 | 27 Mar 2025 |
30İzleyin | CVE-2025-26886İstismar yok | WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerabilitypublishpress · publishpress authors · CWE-89 | Yüksek7,6 | — | %0,4 | 15 Mar 2025 |
39İzleyin | CVE-2025-26971İstismar yok | WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerabilityays-pro · poll maker · CWE-89 | Kritik9,8 | — | %0,5 | 25 Şub 2025 |
26İzleyin | CVE-2025-26769İstismar yok | WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerabilitywebilia inc. · vertex addons for elementor · CWE-79 | Orta6,5 | — | %0,2 | 17 Şub 2025 |
26İzleyin | CVE-2025-22662İstismar yok | WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerabilitysendpulse · sendpulse email marketing newsletter · CWE-79 | Orta6,5 | — | %0,2 | 4 Şub 2025 |
30İzleyin | CVE-2025-24659Kavram kanıtı | WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerabilityshahjada · wpdm – premium packages · CWE-89 | Yüksek7,6 | — | %1,0 | 24 Oca 2025 |
40Planlayın | CVE-2025-24587Kavram kanıtı | WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerabilitynks · email subscription popup · CWE-89 | Yüksek7,6 | — | %32,2 | 24 Oca 2025 |
30İzleyin | CVE-2025-22710Kavram kanıtı | WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerabilitystoreapps · smart manager · CWE-89 | Yüksek7,6 | — | %0,8 | 21 Oca 2025 |
28İzleyin | CVE-2025-22510Kavram kanıtı | WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerabilitykkarpieszuk · wc price history for omnibus · CWE-502 | Yüksek7,2 | — | %1,2 | 9 Oca 2025 |
30İzleyin | CVE-2025-22352Kavram kanıtı | WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerabilityelextensions · elex woocommerce advanced bulk edit products, prices & attributes · CWE-89 | Yüksek7,6 | — | %0,7 | 7 Oca 2025 |
28İzleyin | CVE-2024-56289Kavram kanıtı | WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerabilityadrian tobey · groundhogg · CWE-79 | Yüksek7,1 | — | %0,7 | 7 Oca 2025 |
37İzleyin | CVE-2024-56278Kavram kanıtı | WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerabilitysmackcoders inc., · wp ultimate exporter · CWE-94 | Kritik9,1 | — | %1,9 | 7 Oca 2025 |
- CVE-2025-3213523İzleyin
WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,9İstismar yokEPSS %0rocketelements · split test for elementor4 Nis 2025
- CVE-2025-3186423İzleyin
WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,9Kavram kanıtıEPSS %0out the box · beam me up scotty1 Nis 2025
- CVE-2025-2278335İzleyin
WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability
YüksekCVSS 8,8Kavram kanıtıEPSS %1squirrly · seo plugin by squirrly seo27 Mar 2025
- CVE-2025-2265230İzleyin
WordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %1kendysond · payment forms for paystack27 Mar 2025
- CVE-2025-3092130İzleyin
WordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %1tribulant software · newsletters27 Mar 2025
- CVE-2025-2688630İzleyin
WordPress PublishPress Authors plugin <= 4.7.3 - SQL Injection vulnerability
YüksekCVSS 7,6İstismar yokEPSS %0publishpress · publishpress authors15 Mar 2025
- CVE-2025-2697139İzleyin
WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerability
KritikCVSS 9,8İstismar yokEPSS %0ays-pro · poll maker25 Şub 2025
- CVE-2025-2676926İzleyin
WordPress Vertex Addons for Elementor plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0webilia inc. · vertex addons for elementor17 Şub 2025
- CVE-2025-2266226İzleyin
WordPress SendPulse Email Marketing Newsletter plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0sendpulse · sendpulse email marketing newsletter4 Şub 2025
- CVE-2025-2465930İzleyin
WordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %1shahjada · wpdm – premium packages24 Oca 2025
- CVE-2025-2458740Planlayın
WordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %32nks · email subscription popup24 Oca 2025
- CVE-2025-2271030İzleyin
WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %1storeapps · smart manager21 Oca 2025
- CVE-2025-2251028İzleyin
WordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerability
YüksekCVSS 7,2Kavram kanıtıEPSS %1kkarpieszuk · wc price history for omnibus9 Oca 2025
- CVE-2025-2235230İzleyin
WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerability
YüksekCVSS 7,6Kavram kanıtıEPSS %1elextensions · elex woocommerce advanced bulk edit products, prices & attributes7 Oca 2025
- CVE-2024-5628928İzleyin
WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
YüksekCVSS 7,1Kavram kanıtıEPSS %1adrian tobey · groundhogg7 Oca 2025
- CVE-2024-5627837İzleyin
WordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability
KritikCVSS 9,1Kavram kanıtıEPSS %2smackcoders inc., · wp ultimate exporter7 Oca 2025