BoldGrid kayıtları
boldgrid üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %7,4
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %14,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-862 Missing Authorization3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2013-2010Silahlaştırılmış | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerabilityautomattic · wp super cache · CWE-74 | Kritik9,8 | — | %73,9 | 12 Şub 2020 |
36İzleyin | CVE-2019-6715Kavram kanıtı | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL fieboldgrid · w3 total cache | Yüksek7,5 | — | %19,4 | 1 Nis 2019 |
35İzleyin | CVE-2024-12365Kavram kanıtı | W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgeryboldgrid · w3 total cache · CWE-862 | Yüksek8,5 | — | %1,8 | 14 Oca 2025 |
35İzleyin | CVE-2023-25480İstismar yok | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF)boldgrid · post and page builder · CWE-352 | Yüksek8,8 | — | %0,3 | 6 Eki 2023 |
32İzleyin | CVE-2012-6077Kavram kanıtı | W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.boldgrid · w3 total cache · CWE-200 | Yüksek7,5 | — | %5,4 | 22 Kas 2019 |
31İzleyin | CVE-2012-6078İstismar yok | W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.boldgrid · w3 total cache · CWE-200 | Yüksek7,5 | — | %2,3 | 22 Kas 2019 |
31İzleyin | CVE-2024-12008Kavram kanıtı | W3 Total Cache <= 2.8.1 Information Exposure via Log Filesboldgrid · w3 total cache · CWE-200 | Yüksek7,5 | — | %2,3 | 14 Oca 2025 |
31İzleyin | CVE-2012-6079İstismar yok | W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via tboldgrid · w3 total cache · CWE-200 | Yüksek7,5 | — | %2,1 | 22 Kas 2019 |
30İzleyin | CVE-2020-36848Silahlaştırılmış | Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Downloadboldgrid · total upkeep · CWE-200 | Yüksek7,5 | — | %1,6 | 12 Tem 2025 |
30İzleyin | CVE-2023-5359Kavram kanıtı | W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintextboldgrid · w3 total cache · CWE-200 | Yüksek7,5 | — | %0,8 | 24 Eyl 2024 |
30İzleyin | CVE-2024-24869İstismar yok | WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerabilityboldgrid · total upkeep · CWE-22 | Yüksek7,5 | — | %0,7 | 17 May 2024 |
28İzleyin | CVE-2024-9461İstismar yok | Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settingsboldgrid · total upkeep · CWE-78 | Yüksek7,2 | — | %1,0 | 26 Kas 2024 |
28İzleyin | CVE-2025-2257İstismar yok | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injectionboldgrid · total upkeep · CWE-78 | Yüksek7,2 | — | %0,9 | 26 Mar 2025 |
27İzleyin | CVE-2014-9414İstismar yok | The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct crossboldgrid · w3 total cache · CWE-352 | Orta6,8 | — | %1,4 | 24 Ara 2014 |
26İzleyin | CVE-2025-0859İstismar yok | Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Functionboldgrid · post and page builder · CWE-22 | Orta6,5 | — | %0,7 | 6 Şub 2025 |
26İzleyin | CVE-2024-13907İstismar yok | Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgeryboldgrid · total upkeep · CWE-918 | Orta6,5 | — | %0,5 | 27 Şub 2025 |
25İzleyin | CVE-2021-24452Kavram kanıtı | W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)boldgrid · w3 total cache · CWE-79 | Orta6,1 | — | %1,9 | 19 Tem 2021 |
25İzleyin | CVE-2021-24436Kavram kanıtı | W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)boldgrid · w3 total cache · CWE-79 | Orta6,1 | — | %1,9 | 19 Tem 2021 |
21İzleyin | CVE-2024-12006İstismar yok | W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivationboldgrid · w3 total cache · CWE-862 | Orta5,3 | — | %0,5 | 14 Oca 2025 |
21İzleyin | CVE-2024-2950İstismar yok | BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposureboldgrid · easy seo · CWE-200 | Orta5,3 | — | %0,5 | 6 Nis 2024 |
21İzleyin | CVE-2024-6848İstismar yok | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Uploadboldgrid · post and page builder · CWE-79 | Orta5,4 | — | %0,5 | 20 Tem 2024 |
21İzleyin | CVE-2024-2888İstismar yok | WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerabilityboldgrid · post and page builder · CWE-79 | Orta5,4 | — | %0,3 | 26 Mar 2024 |
21İzleyin | CVE-2025-22759İstismar yok | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerabilityboldgrid · post and page builder by boldgrid - visual drag and drop editor · CWE-79 | Orta5,4 | — | %0,3 | 15 Oca 2025 |
21İzleyin | CVE-2024-4400İstismar yok | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scriptingboldgrid · post and page builder · CWE-79 | Orta5,4 | — | %0,3 | 16 May 2024 |
19İzleyin | CVE-2021-24427İstismar yok | W3 Total Cache < 2.1.3 - Authenticated Stored XSSboldgrid · w3 total cache · CWE-79 | Orta4,8 | — | %0,6 | 12 Tem 2021 |
- CVE-2013-201061Bu hafta
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %74automattic · wp super cache12 Şub 2020
- CVE-2019-671536İzleyin
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL fie
YüksekCVSS 7,5Kavram kanıtıEPSS %19boldgrid · w3 total cache1 Nis 2019
- CVE-2024-1236535İzleyin
W3 Total Cache <= 2.8.1 - Authenticated (Subscriber+) Missing Authorization to Server-Side Request Forgery
YüksekCVSS 8,5Kavram kanıtıEPSS %2boldgrid · w3 total cache14 Oca 2025
- CVE-2023-2548035İzleyin
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0boldgrid · post and page builder6 Eki 2023
- CVE-2012-607732İzleyin
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
YüksekCVSS 7,5Kavram kanıtıEPSS %5boldgrid · w3 total cache22 Kas 2019
- CVE-2012-607831İzleyin
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
YüksekCVSS 7,5İstismar yokEPSS %2boldgrid · w3 total cache22 Kas 2019
- CVE-2024-1200831İzleyin
W3 Total Cache <= 2.8.1 Information Exposure via Log Files
YüksekCVSS 7,5Kavram kanıtıEPSS %2boldgrid · w3 total cache14 Oca 2025
- CVE-2012-607931İzleyin
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via t
YüksekCVSS 7,5İstismar yokEPSS %2boldgrid · w3 total cache22 Kas 2019
- CVE-2020-3684830İzleyin
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
YüksekCVSS 7,5SilahlaştırılmışEPSS %2boldgrid · total upkeep12 Tem 2025
- CVE-2023-535930İzleyin
W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
YüksekCVSS 7,5Kavram kanıtıEPSS %1boldgrid · w3 total cache24 Eyl 2024
- CVE-2024-2486930İzleyin
WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1boldgrid · total upkeep17 May 2024
- CVE-2024-946128İzleyin
Total Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup Settings
YüksekCVSS 7,2İstismar yokEPSS %1boldgrid · total upkeep26 Kas 2024
- CVE-2025-225728İzleyin
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection
YüksekCVSS 7,2İstismar yokEPSS %1boldgrid · total upkeep26 Mar 2025
- CVE-2014-941427İzleyin
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross
OrtaCVSS 6,8İstismar yokEPSS %1boldgrid · w3 total cache24 Ara 2014
- CVE-2025-085926İzleyin
Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function
OrtaCVSS 6,5İstismar yokEPSS %1boldgrid · post and page builder6 Şub 2025
- CVE-2024-1390726İzleyin
Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.8 - Authenticated (Administrator+) Server-Side Request Forgery
OrtaCVSS 6,5İstismar yokEPSS %0boldgrid · total upkeep27 Şub 2025
- CVE-2021-2445225İzleyin
W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context)
OrtaCVSS 6,1Kavram kanıtıEPSS %2boldgrid · w3 total cache19 Tem 2021
- CVE-2021-2443625İzleyin
W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context)
OrtaCVSS 6,1Kavram kanıtıEPSS %2boldgrid · w3 total cache19 Tem 2021
- CVE-2024-1200621İzleyin
W3 Total Cache <= 2.8.1 Missing Authorization to Unauthenticated Plugin Deactivation and Extensions Activation/Deactivation
OrtaCVSS 5,3İstismar yokEPSS %1boldgrid · w3 total cache14 Oca 2025
- CVE-2024-295021İzleyin
BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %1boldgrid · easy seo6 Nis 2024
- CVE-2024-684821İzleyin
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload
OrtaCVSS 5,4İstismar yokEPSS %0boldgrid · post and page builder20 Tem 2024
- CVE-2024-288821İzleyin
WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0boldgrid · post and page builder26 Mar 2024
- CVE-2025-2275921İzleyin
WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0boldgrid · post and page builder by boldgrid - visual drag and drop editor15 Oca 2025
- CVE-2024-440021İzleyin
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0boldgrid · post and page builder16 May 2024
- CVE-2021-2442719İzleyin
W3 Total Cache < 2.1.3 - Authenticated Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %1boldgrid · w3 total cache12 Tem 2021