bbPress kayıtları
bbpress üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2020-13693Kavram kanıtı | An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.bbpress · bbpress | Kritik9,8 | — | %43,9 | 28 May 2020 |
31İzleyin | CVE-2007-3244İstismar yok | SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrarbbpress · bbpress | Yüksek7,5 | — | %1,8 | 14 Haz 2007 |
24İzleyin | CVE-2011-1150İstismar yok | bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.bbpress · bbpress · CWE-79 | Orta6,1 | — | %0,9 | 5 Şub 2020 |
20İzleyin | CVE-2011-3710İstismar yok | bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pabbpress · bbpress · CWE-200 | Orta5,0 | — | %1,6 | 23 Eyl 2011 |
19İzleyin | CVE-2020-13487İstismar yok | The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/ebbpress · bbpress · CWE-79 | Orta4,8 | — | %1,6 | 26 May 2020 |
18İzleyin | CVE-2007-3243Kavram kanıtı | Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML viabbpress · bbpress | Orta4,3 | — | %1,8 | 14 Haz 2007 |
- CVE-2020-1369352Planlayın
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.
KritikCVSS 9,8Kavram kanıtıEPSS %44bbpress · bbpress28 May 2020
- CVE-2007-324431İzleyin
SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrar
YüksekCVSS 7,5İstismar yokEPSS %2bbpress · bbpress14 Haz 2007
- CVE-2011-115024İzleyin
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
OrtaCVSS 6,1İstismar yokEPSS %1bbpress · bbpress5 Şub 2020
- CVE-2011-371020İzleyin
bbPress 1.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa
OrtaCVSS 5,0İstismar yokEPSS %2bbpress · bbpress23 Eyl 2011
- CVE-2020-1348719İzleyin
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/e
OrtaCVSS 4,8İstismar yokEPSS %2bbpress · bbpress26 May 2020
- CVE-2007-324318İzleyin
Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3Kavram kanıtıEPSS %2bbpress · bbpress14 Haz 2007