CWE-82 · 8 kayıt
Improper Neutralization of Script in Attributes of IMG Tags in a Web Page
Bu sınıftaki CVE’ler
8 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2024-48042İstismar yok | WordPress Contact Form by Supsystic plugin <= 1.7.28 - Remote Code Execution (RCE) vulnerabilitysupsystic · contact form by supsystic · CWE-82 | Kritik9,1 | — | %1,1 | 16 Eki 2024 |
36İzleyin | CVE-2024-52434İstismar yok | WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerabilitysupsystic · popup · CWE-82 | Kritik9,1 | — | %1,1 | 18 Kas 2024 |
35İzleyin | CVE-2024-52427İstismar yok | WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerabilityvollstart · event tickets with ticket scanner · CWE-82 | Yüksek8,8 | — | %0,7 | 18 Kas 2024 |
34İzleyin | CVE-2025-53194İstismar yok | WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerabilitycrocoblock · jetengine · CWE-82 | Yüksek8,5 | — | %0,4 | 20 Ağu 2025 |
28İzleyin | CVE-2024-49271İstismar yok | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerabilityunlimited-elements · unlimited elements for elementor · CWE-82 | Yüksek7,2 | — | %1,1 | 16 Eki 2024 |
28İzleyin | CVE-2024-52393İstismar yok | WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerabilitypodlove · podlove podcast publisher · CWE-82 | Yüksek7,2 | — | %0,5 | 14 Kas 2024 |
21İzleyin | CVE-2026-56735İstismar yok | Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammadzammad · zammad · CWE-82 | Orta5,3 | — | %0,4 | 4 gün önce |
21İzleyin | CVE-2023-30963İstismar yok | Stored XSS in Foundry Slate Query Dropdown menupalantir · foundry frontend · CWE-82 | Orta5,4 | — | %0,4 | 10 Tem 2023 |
- CVE-2024-4804236İzleyin
WordPress Contact Form by Supsystic plugin <= 1.7.28 - Remote Code Execution (RCE) vulnerability
KritikCVSS 9,1İstismar yokEPSS %1supsystic · contact form by supsystic16 Eki 2024
- CVE-2024-5243436İzleyin
WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability
KritikCVSS 9,1İstismar yokEPSS %1supsystic · popup18 Kas 2024
- CVE-2024-5242735İzleyin
WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1vollstart · event tickets with ticket scanner18 Kas 2024
- CVE-2025-5319434İzleyin
WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerability
YüksekCVSS 8,5İstismar yokEPSS %0crocoblock · jetengine20 Ağu 2025
- CVE-2024-4927128İzleyin
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1unlimited-elements · unlimited elements for elementor16 Eki 2024
- CVE-2024-5239328İzleyin
WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1podlove · podlove podcast publisher14 Kas 2024
- CVE-2026-5673521İzleyin
Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad
OrtaCVSS 5,3İstismar yokEPSS %0zammad · zammad4 gün önce
- CVE-2023-3096321İzleyin
Stored XSS in Foundry Slate Query Dropdown menu
OrtaCVSS 5,4İstismar yokEPSS %0palantir · foundry frontend10 Tem 2023