İçeriğe atla
Noroxi

BestWebSoft kayıtları

bestwebsoft üreticisine ait 75 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%26,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

75 kayıt
  • CVE-2015-9325
    40Planlayın

    The visitors-online plugin before 0.4 for WordPress has SQL injection.

    KritikCVSS 9,8İstismar yokEPSS %2

    bestwebsoft · visitors online16 Ağu 2019

  • CVE-2015-9335
    40Planlayın

    The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

    KritikCVSS 9,8İstismar yokEPSS %2

    bestwebsoft · limit attempts22 Ağu 2019

  • CVE-2022-3393
    39İzleyin

    Post to CSV by BestWebSoft <= 1.4.0 - Author+ CSV Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    bestwebsoft · post to csv25 Eki 2022

  • CVE-2023-36508
    39İzleyin

    WordPress Contact Form to DB by BestWebSoft Plugin <= 1.7.1 is vulnerable to SQL Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    bestwebsoft · contact form to db31 Eki 2023

  • CVE-2020-8658
    38İzleyin

    The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF.

    YüksekCVSS 8,8İstismar yokEPSS %10

    bestwebsoft · htaccess5 Şub 2020

  • CVE-2023-0765
    35İzleyin

    Gallery by BestWebSoft < 4.7.0 - Author+ SQL Injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    bestwebsoft · gallery17 Nis 2023

  • CVE-2023-29096
    35İzleyin

    WordPress Contact Form to DB by BestWebSoft Plugin <= 1.7.0 is vulnerable to SQL Injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    bestwebsoft · contact form to db20 Ara 2023

  • CVE-2023-36527
    35İzleyin

    WordPress Post to CSV by BestWebSoft Plugin <= 1.4.0 is vulnerable to CSV Injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    bestwebsoft · post to csv7 Kas 2023

  • CVE-2024-35678
    35İzleyin

    WordPress Contact Form to DB by BestWebSoft plugin <= 1.7.2 - SQL Injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    bestwebsoft · contact form to db8 Haz 2024

  • CVE-2012-10015
    35İzleyin

    BestWebSoft Twitter Plugin Settings Page twitter.php twttr_settings_page cross-site request forgery

    YüksekCVSS 8,8İstismar yokEPSS %0

    bestwebsoft · twitter30 May 2023

  • CVE-2023-0820
    35İzleyin

    User Role by BestWebSoft < 1.6.7 - Privilege Escalation via CSRF

    YüksekCVSS 8,8İstismar yokEPSS %0

    bestwebsoft · user role3 Nis 2023

  • CVE-2012-10010
    35İzleyin

    BestWebSoft Contact Form contact_form.php cntctfrm_settings_page cross-site request forgery

    YüksekCVSS 8,8İstismar yokEPSS %0

    bestwebsoft · contact form9 Nis 2023

  • CVE-2012-10017
    35İzleyin

    BestWebSoft Portfolio Plugin cross-site request forgery

    YüksekCVSS 8,8İstismar yokEPSS %0

    bestwebsoft · portfolio26 Ara 2023

  • CVE-2012-10012
    35İzleyin

    BestWebSoft Facebook Like Button facebook-button-plugin.php fcbk_bttn_plgn_settings_page cross-site request forgery

    YüksekCVSS 8,8İstismar yokEPSS %0

    bestwebsoft · facebook button9 Nis 2023

  • CVE-2014-125102
    30İzleyin

    Bestwebsoft Relevant Plugin Thumbnail information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %1

    bestwebsoft · relevant29 May 2023

  • CVE-2023-6250
    30İzleyin

    BestWebSoft's Like & Share < 2.74 - Unauthenticated Password Protected Post Read

    YüksekCVSS 7,5İstismar yokEPSS %0

    bestwebsoft · like \& share26 Ara 2023

  • CVE-2024-13908
    28İzleyin

    SMTP by BestWebSoft <= 1.1.9 - Authenticated (Administrator+) Arbitrary File Upload

    YüksekCVSS 7,2İstismar yokEPSS %1

    bestwebsoft · smtp8 Mar 2025

  • CVE-2023-45771
    28İzleyin

    WordPress Contact Form With Captcha plugin <= 1.6.8 - Reflected Cross Site Scripting (XSS) vulnerability

    YüksekCVSS 7,1İstismar yokEPSS %0

    bestwebsoft · captcha26 Mar 2024

  • CVE-2021-25121
    26İzleyin

    Rating by BestWebSoft < 1.6 - Rating Denial of Service

    OrtaCVSS 6,5İstismar yokEPSS %1

    bestwebsoft · rating20 Haz 2022

  • CVE-2021-24761
    26İzleyin

    Error Log Viewer < 1.1.2 - Arbitrary Text File Deletion via CSRF

    OrtaCVSS 6,5İstismar yokEPSS %1

    bestwebsoft · error log viewer1 Şub 2022

  • CVE-2023-6821
    26İzleyin

    Error Log Viewer < 1.1.3 - Directory Listing to Sensitive Data Exposure

    OrtaCVSS 6,5İstismar yokEPSS %1

    bestwebsoft · error log viewer18 Mar 2024

  • CVE-2017-18528
    25İzleyin

    The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    bestwebsoft · pdf \& print20 Ağu 2019

  • CVE-2017-18527
    25İzleyin

    The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    bestwebsoft · pagination20 Ağu 2019

  • CVE-2017-18516
    25İzleyin

    The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    bestwebsoft · linkedin21 Ağu 2019

  • CVE-2017-18502
    24İzleyin

    The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    bestwebsoft · subscriber12 Ağu 2019