codection kayıtları
codection üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %11,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File2
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-201 Insertion of Sensitive Information Into Sent Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2024-8252Kavram kanıtı | Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusioncodection · clean login · CWE-98 | Yüksek8,8 | — | %3,0 | 30 Ağu 2024 |
35İzleyin | CVE-2019-15329İstismar yok | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.codection · import users from csv with meta · CWE-352 | Yüksek8,8 | — | %0,7 | 22 Ağu 2019 |
33İzleyin | CVE-2020-22277İstismar yok | Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.codection · import and export users and customers · CWE-1236 | Yüksek8,0 | — | %1,9 | 4 Kas 2020 |
32İzleyin | CVE-2022-3558İstismar yok | Import and export users and customers < 1.20.5 - Subscriber+ CSV Injectioncodection · import and export users and customers · CWE-1236 | Yüksek8,0 | — | %1,1 | 7 Kas 2022 |
31İzleyin | CVE-2019-15326İstismar yok | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.codection · import users from csv with meta · CWE-22 | Yüksek7,5 | — | %2,3 | 22 Ağu 2019 |
30İzleyin | CVE-2024-38787İstismar yok | WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerabilityjavier carazo · import and export users and customers · CWE-201 | Yüksek7,5 | — | %0,4 | 13 Ağu 2024 |
28İzleyin | CVE-2023-6583İstismar yok | Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionalitycodection · import and export users and customers · CWE-98 | Yüksek7,2 | — | %0,8 | 11 Oca 2024 |
26İzleyin | CVE-2017-8875İstismar yok | CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.codection · clean login · CWE-352 | Orta6,5 | — | %0,6 | 10 May 2017 |
24İzleyin | CVE-2019-15328İstismar yok | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.codection · import users from csv with meta · CWE-79 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
24İzleyin | CVE-2015-9336İstismar yok | The clean-login plugin before 1.5.1 for WordPress has reflected XSS.codection · clean login · CWE-79 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
24İzleyin | CVE-2019-15327İstismar yok | The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.codection · import users from csv with meta · CWE-79 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
24İzleyin | CVE-2018-20101İstismar yok | The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.codection · import users from csv with meta · CWE-79 | Orta6,1 | — | %0,8 | 12 Ara 2018 |
22İzleyin | CVE-2019-14683İstismar yok | The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attaccodection · import users from csv with meta · CWE-352 | Orta5,7 | — | %0,7 | 8 Ağu 2019 |
21İzleyin | CVE-2022-4838İstismar yok | Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcodecodection · clean login · CWE-79 | Orta5,4 | — | %0,6 | 6 Şub 2023 |
21İzleyin | CVE-2023-6624İstismar yok | Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcodecodection · import and export users and customers · CWE-79 | Orta5,4 | — | %0,3 | 11 Oca 2024 |
21İzleyin | CVE-2024-22151İstismar yok | WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerabilitycodection · import and export users and customers · CWE-862 | Orta5,3 | — | %0,3 | 8 Haz 2024 |
19İzleyin | CVE-2022-1255İstismar yok | Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scriptingcodection · import and export users and customers · CWE-79 | Orta4,8 | — | %0,7 | 2 May 2022 |
17İzleyin | CVE-2024-4734İstismar yok | Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scriptingcarazo · import and export users and customers · CWE-79 | Orta4,4 | — | %0,3 | 14 May 2024 |
- CVE-2024-825236İzleyin
Clean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion
YüksekCVSS 8,8Kavram kanıtıEPSS %3codection · clean login30 Ağu 2024
- CVE-2019-1532935İzleyin
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1codection · import users from csv with meta22 Ağu 2019
- CVE-2020-2227733İzleyin
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
YüksekCVSS 8,0İstismar yokEPSS %2codection · import and export users and customers4 Kas 2020
- CVE-2022-355832İzleyin
Import and export users and customers < 1.20.5 - Subscriber+ CSV Injection
YüksekCVSS 8,0İstismar yokEPSS %1codection · import and export users and customers7 Kas 2022
- CVE-2019-1532631İzleyin
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
YüksekCVSS 7,5İstismar yokEPSS %2codection · import users from csv with meta22 Ağu 2019
- CVE-2024-3878730İzleyin
WordPress Import and export users and customers plugin <= 1.26.8 - Sensitive Information via Imported File vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0javier carazo · import and export users and customers13 Ağu 2024
- CVE-2023-658328İzleyin
Import and export users and customers <= 1.24.2 - Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality
YüksekCVSS 7,2İstismar yokEPSS %1codection · import and export users and customers11 Oca 2024
- CVE-2017-887526İzleyin
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
OrtaCVSS 6,5İstismar yokEPSS %1codection · clean login10 May 2017
- CVE-2019-1532824İzleyin
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1codection · import users from csv with meta22 Ağu 2019
- CVE-2015-933624İzleyin
The clean-login plugin before 1.5.1 for WordPress has reflected XSS.
OrtaCVSS 6,1İstismar yokEPSS %1codection · clean login22 Ağu 2019
- CVE-2019-1532724İzleyin
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
OrtaCVSS 6,1İstismar yokEPSS %1codection · import users from csv with meta22 Ağu 2019
- CVE-2018-2010124İzleyin
The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell.
OrtaCVSS 6,1İstismar yokEPSS %1codection · import users from csv with meta12 Ara 2018
- CVE-2019-1468322İzleyin
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attac
OrtaCVSS 5,7İstismar yokEPSS %1codection · import users from csv with meta8 Ağu 2019
- CVE-2022-483821İzleyin
Clean Login < 1.13.7 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %1codection · clean login6 Şub 2023
- CVE-2023-662421İzleyin
Import and export users and customers <= 1.24.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
OrtaCVSS 5,4İstismar yokEPSS %0codection · import and export users and customers11 Oca 2024
- CVE-2024-2215121İzleyin
WordPress Import and export users and customers plugin <= 1.24.6 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0codection · import and export users and customers8 Haz 2024
- CVE-2022-125519İzleyin
Import and export users and customers < 1.19.2.1 - Admin+ Stored Cross-Site Scripting
OrtaCVSS 4,8İstismar yokEPSS %1codection · import and export users and customers2 May 2022
- CVE-2024-473417İzleyin
Import and export users and customers <= 1.26.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
OrtaCVSS 4,4İstismar yokEPSS %0carazo · import and export users and customers14 May 2024