advancedcustomfields kayıtları
advancedcustomfields üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %29,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-862 Missing Authorization4
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2015-9479İstismar yok | The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQueryadvancedcustomfields · acf fronted display · CWE-434 | Kritik9,8 | — | %2,8 | 10 Eki 2019 |
36İzleyin | CVE-2023-30777Kavram kanıtı | WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)advancedcustomfields · advanced custom fields · CWE-79 | Orta6,1 | — | %38,8 | 10 May 2023 |
35İzleyin | CVE-2022-2594İstismar yok | Advanced Custom Fields 5.0-5.12.2 - Unauthenticated File Uploadadvancedcustomfields · advanced custom fields · CWE-434 | Yüksek8,8 | — | %1,6 | 22 Ağu 2022 |
35İzleyin | CVE-2023-1196İstismar yok | Advanced Custom Fields - Contributor+ PHP Object Injectionadvancedcustomfields · advanced custom fields · CWE-502 | Yüksek8,8 | — | %1,1 | 2 May 2023 |
34İzleyin | CVE-2024-34761İstismar yok | Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Arbitrary Function Execution vulnerabilitywpengine inc · advanced custom fields pro · CWE-94 | Yüksek8,5 | — | %0,4 | 10 Haz 2024 |
31İzleyin | CVE-2021-20865İstismar yok | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerabadvancedcustomfields · advanced custom fields · CWE-862 | Yüksek7,5 | — | %2,5 | 13 Ara 2021 |
30İzleyin | CVE-2022-40696İstismar yok | WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposureadvancedcustomfields · advanced custom fields · CWE-200 | Yüksek7,5 | — | %0,5 | 8 Oca 2024 |
26İzleyin | CVE-2021-20866İstismar yok | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerabadvancedcustomfields · advanced custom fields · CWE-862 | Orta6,5 | — | %1,7 | 13 Ara 2021 |
26İzleyin | CVE-2022-23183İstismar yok | Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12advancedcustomfields · advanced custom fields · CWE-862 | Orta6,5 | — | %1,5 | 31 Mar 2022 |
26İzleyin | CVE-2021-20867İstismar yok | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerabadvancedcustomfields · advanced custom fields · CWE-862 | Orta6,5 | — | %1,4 | 13 Ara 2021 |
26İzleyin | CVE-2024-9529İstismar yok | Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Executionadvancedcustomfields · advanced custom fields · CWE-94 | Orta6,6 | — | %0,4 | 15 Kas 2024 |
26İzleyin | CVE-2024-4565İstismar yok | Advanced Custom Fields < 6.3 - Contributor+ Custom Field Accessadvancedcustomfields · advanced custom fields · CWE-639 | Orta6,5 | — | %0,4 | 20 Haz 2024 |
24İzleyin | CVE-2021-24241İstismar yok | Advanced Custom Field Pro < 5.9.1 - Reflected Cross-Site Scripting (XSS)advancedcustomfields · advanced custom fields · CWE-79 | Orta6,1 | — | %1,4 | 22 Nis 2021 |
24İzleyin | CVE-2020-36172İstismar yok | The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading tadvancedcustomfields · advanced custom fields · CWE-79 | Orta6,1 | — | %0,9 | 6 Oca 2021 |
22İzleyin | CVE-2023-40068İstismar yok | Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7 advancedcustomfields · advanced custom fields · CWE-79 | Orta5,4 | — | %2,0 | 21 Ağu 2023 |
21İzleyin | CVE-2018-20986İstismar yok | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.advancedcustomfields · advanced custom fields · CWE-79 | Orta5,4 | — | %0,9 | 22 Ağu 2019 |
21İzleyin | CVE-2023-6701İstismar yok | Advanced Custom Fields <= 6.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fieldadvancedcustomfields · advanced custom fields · CWE-79 | Orta5,4 | — | %0,5 | 5 Şub 2024 |
- CVE-2015-947940Planlayın
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery
KritikCVSS 9,8İstismar yokEPSS %3advancedcustomfields · acf fronted display10 Eki 2019
- CVE-2023-3077736İzleyin
WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1Kavram kanıtıEPSS %39advancedcustomfields · advanced custom fields10 May 2023
- CVE-2022-259435İzleyin
Advanced Custom Fields 5.0-5.12.2 - Unauthenticated File Upload
YüksekCVSS 8,8İstismar yokEPSS %2advancedcustomfields · advanced custom fields22 Ağu 2022
- CVE-2023-119635İzleyin
Advanced Custom Fields - Contributor+ PHP Object Injection
YüksekCVSS 8,8İstismar yokEPSS %1advancedcustomfields · advanced custom fields2 May 2023
- CVE-2024-3476134İzleyin
Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Arbitrary Function Execution vulnerability
YüksekCVSS 8,5İstismar yokEPSS %0wpengine inc · advanced custom fields pro10 Haz 2024
- CVE-2021-2086531İzleyin
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerab
YüksekCVSS 7,5İstismar yokEPSS %2advancedcustomfields · advanced custom fields13 Ara 2021
- CVE-2022-4069630İzleyin
WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5İstismar yokEPSS %1advancedcustomfields · advanced custom fields8 Oca 2024
- CVE-2021-2086626İzleyin
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerab
OrtaCVSS 6,5İstismar yokEPSS %2advancedcustomfields · advanced custom fields13 Ara 2021
- CVE-2022-2318326İzleyin
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro versions prior to 5.12
OrtaCVSS 6,5İstismar yokEPSS %1advancedcustomfields · advanced custom fields31 Mar 2022
- CVE-2021-2086726İzleyin
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerab
OrtaCVSS 6,5İstismar yokEPSS %1advancedcustomfields · advanced custom fields13 Ara 2021
- CVE-2024-952926İzleyin
Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution
OrtaCVSS 6,6İstismar yokEPSS %0advancedcustomfields · advanced custom fields15 Kas 2024
- CVE-2024-456526İzleyin
Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access
OrtaCVSS 6,5İstismar yokEPSS %0advancedcustomfields · advanced custom fields20 Haz 2024
- CVE-2021-2424124İzleyin
Advanced Custom Field Pro < 5.9.1 - Reflected Cross-Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %1advancedcustomfields · advanced custom fields22 Nis 2021
- CVE-2020-3617224İzleyin
The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading t
OrtaCVSS 6,1İstismar yokEPSS %1advancedcustomfields · advanced custom fields6 Oca 2021
- CVE-2023-4006822İzleyin
Cross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to 6.1.7
OrtaCVSS 5,4İstismar yokEPSS %2advancedcustomfields · advanced custom fields21 Ağu 2023
- CVE-2018-2098621İzleyin
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
OrtaCVSS 5,4İstismar yokEPSS %1advancedcustomfields · advanced custom fields22 Ağu 2019
- CVE-2023-670121İzleyin
Advanced Custom Fields <= 6.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
OrtaCVSS 5,4İstismar yokEPSS %1advancedcustomfields · advanced custom fields5 Şub 2024