cformsii project kayıtları
cformsii project üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %11,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2015-9333İstismar yok | The cforms2 plugin before 14.6.10 for WordPress has SQL injection.cformsii project · cformsii · CWE-89 | Kritik9,8 | — | %1,8 | 22 Ağu 2019 |
40Planlayın | CVE-2017-18570İstismar yok | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.cformsii project · cformsii · CWE-89 | Kritik9,8 | — | %1,8 | 22 Ağu 2019 |
35İzleyin | CVE-2019-15238İstismar yok | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.cformsii project · cformsii · CWE-352 | Yüksek8,8 | — | %0,7 | 20 Ağu 2019 |
35İzleyin | CVE-2023-25449İstismar yok | WordPress CformsII Plugin <=15.0.4 is vulnerable to Cross Site Request Forgery (CSRF)cformsii project · cformsii · CWE-352 | Yüksek8,8 | — | %0,3 | 15 Haz 2023 |
24İzleyin | CVE-2014-10392İstismar yok | The cforms2 plugin before 10.2 for WordPress has XSS.cformsii project · cformsii · CWE-79 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
24İzleyin | CVE-2014-10377İstismar yok | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.cformsii project · cformsii · CWE-79 | Orta6,1 | — | %0,9 | 21 Ağu 2019 |
24İzleyin | CVE-2017-18559İstismar yok | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.cformsii project · cformsii · CWE-79 | Orta6,1 | — | %0,9 | 21 Ağu 2019 |
24İzleyin | CVE-2014-10393İstismar yok | The cforms2 plugin before 10.5 for WordPress has XSS.cformsii project · cformsii · CWE-79 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
19İzleyin | CVE-2023-52203İstismar yok | WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS)cformsii project · cformsii · CWE-79 | Orta4,8 | — | %0,3 | 8 Oca 2024 |
- CVE-2015-933340Planlayın
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
KritikCVSS 9,8İstismar yokEPSS %2cformsii project · cformsii22 Ağu 2019
- CVE-2017-1857040Planlayın
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
KritikCVSS 9,8İstismar yokEPSS %2cformsii project · cformsii22 Ağu 2019
- CVE-2019-1523835İzleyin
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
YüksekCVSS 8,8İstismar yokEPSS %1cformsii project · cformsii20 Ağu 2019
- CVE-2023-2544935İzleyin
WordPress CformsII Plugin <=15.0.4 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0cformsii project · cformsii15 Haz 2023
- CVE-2014-1039224İzleyin
The cforms2 plugin before 10.2 for WordPress has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1cformsii project · cformsii22 Ağu 2019
- CVE-2014-1037724İzleyin
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
OrtaCVSS 6,1İstismar yokEPSS %1cformsii project · cformsii21 Ağu 2019
- CVE-2017-1855924İzleyin
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
OrtaCVSS 6,1İstismar yokEPSS %1cformsii project · cformsii21 Ağu 2019
- CVE-2014-1039324İzleyin
The cforms2 plugin before 10.5 for WordPress has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1cformsii project · cformsii22 Ağu 2019
- CVE-2023-5220319İzleyin
WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 4,8İstismar yokEPSS %0cformsii project · cformsii8 Oca 2024