8theme kayıtları
8theme üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %53,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-862 Missing Authorization5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-502 Deserialization of Untrusted Data1
- CWE-269 Improper Privilege Management1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-33551İstismar yok | WordPress XStore Core plugin <= 5.3.5 - Unauthenticated SQL Injection vulnerability8theme · xstore core · CWE-89 | Kritik9,8 | — | %0,6 | 29 Nis 2024 |
39İzleyin | CVE-2024-33556İstismar yok | WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerability8theme · xstore core · CWE-434 | Kritik9,8 | — | %0,6 | 17 May 2024 |
39İzleyin | CVE-2024-33553İstismar yok | WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerability8theme · xstore core · CWE-502 | Kritik9,8 | — | %0,6 | 29 Nis 2024 |
39İzleyin | CVE-2024-33552İstismar yok | WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerability8theme · xstore core · CWE-269 | Kritik9,8 | — | %0,6 | 17 May 2024 |
39İzleyin | CVE-2024-33561İstismar yok | WordPress XStore theme <= 9.3.8 - Unauthenticated Broken Access Control vulnerability8theme · xstore · CWE-862 | Kritik9,8 | — | %0,4 | 9 Haz 2024 |
38İzleyin | CVE-2024-33559Kavram kanıtı | WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability8theme · xstore · CWE-89 | Kritik9,3 | — | %3,6 | 29 Nis 2024 |
35İzleyin | CVE-2024-33557İstismar yok | WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability8theme · xstore core · CWE-22 | Yüksek8,8 | — | %0,6 | 4 Haz 2024 |
35İzleyin | CVE-2024-33555İstismar yok | WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerability8theme · xstore core · CWE-862 | Yüksek8,8 | — | %0,4 | 9 Haz 2024 |
35İzleyin | CVE-2024-33563İstismar yok | WordPress XStore theme <= 9.3.8 - Broken Access Control vulnerability8theme · xstore · CWE-862 | Yüksek8,8 | — | %0,4 | 9 Haz 2024 |
28İzleyin | CVE-2024-33562İstismar yok | WordPress XStore theme <= 9.3.5 - Reflected Cross Site Scripting (XSS) vulnerability8theme · xstore · CWE-79 | Yüksek7,1 | — | %0,4 | 29 Nis 2024 |
26İzleyin | CVE-2024-33558İstismar yok | WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerability8theme · xstore core · CWE-862 | Orta6,5 | — | %0,4 | 29 Nis 2024 |
24İzleyin | CVE-2024-33554İstismar yok | WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability8theme · xstore core · CWE-79 | Orta6,1 | — | %0,4 | 29 Nis 2024 |
17İzleyin | CVE-2024-33564İstismar yok | WordPress XStore theme <= 9.3.8 - Arbitrary Option Update vulnerability8theme · xstore · CWE-862 | Orta4,3 | — | %0,3 | 9 Haz 2024 |
- CVE-2024-3355139İzleyin
WordPress XStore Core plugin <= 5.3.5 - Unauthenticated SQL Injection vulnerability
KritikCVSS 9,8İstismar yokEPSS %18theme · xstore core29 Nis 2024
- CVE-2024-3355639İzleyin
WordPress XStore Core plugin <= 5.3.8 - Limited Arbitrary File Upload vulnerability
KritikCVSS 9,8İstismar yokEPSS %18theme · xstore core17 May 2024
- CVE-2024-3355339İzleyin
WordPress XStore Core plugin <= 5.3.5 - Unauthenticated PHP Object Injection vulnerability
KritikCVSS 9,8İstismar yokEPSS %18theme · xstore core29 Nis 2024
- CVE-2024-3355239İzleyin
WordPress XStore Core plugin <= 5.3.8 - Unauthenticated Account Takeover vulnerability
KritikCVSS 9,8İstismar yokEPSS %18theme · xstore core17 May 2024
- CVE-2024-3356139İzleyin
WordPress XStore theme <= 9.3.8 - Unauthenticated Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %08theme · xstore9 Haz 2024
- CVE-2024-3355938İzleyin
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
KritikCVSS 9,3Kavram kanıtıEPSS %48theme · xstore29 Nis 2024
- CVE-2024-3355735İzleyin
WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability
YüksekCVSS 8,8İstismar yokEPSS %18theme · xstore core4 Haz 2024
- CVE-2024-3355535İzleyin
WordPress XStore Core plugin <= 5.3.8 - Multiple Authenticated Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %08theme · xstore core9 Haz 2024
- CVE-2024-3356335İzleyin
WordPress XStore theme <= 9.3.8 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %08theme · xstore9 Haz 2024
- CVE-2024-3356228İzleyin
WordPress XStore theme <= 9.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
YüksekCVSS 7,1İstismar yokEPSS %08theme · xstore29 Nis 2024
- CVE-2024-3355826İzleyin
WordPress XStore Core plugin <= 5.3.5 - Limited Arbitrary File Download vulnerability
OrtaCVSS 6,5İstismar yokEPSS %08theme · xstore core29 Nis 2024
- CVE-2024-3355424İzleyin
WordPress XStore Core plugin <= 5.3.5 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %08theme · xstore core29 Nis 2024
- CVE-2024-3356417İzleyin
WordPress XStore theme <= 9.3.8 - Arbitrary Option Update vulnerability
OrtaCVSS 4,3İstismar yokEPSS %08theme · xstore9 Haz 2024