CodeDropz kayıtları
codedropz üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %6,7
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-73 External Control of File Name or Path1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2020-12800Silahlaştırılmış | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code excodedropz · drag and drop multiple file upload - contact form 7 · CWE-434 | Kritik9,8 | — | %78,6 | 8 Haz 2020 |
41Planlayın | CVE-2025-3515Kavram kanıtı | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checkscodedropz · drag and drop multiple file upload - contact form 7 · CWE-434 | Kritik9,8 | — | %5,8 | 17 Haz 2025 |
40Planlayın | CVE-2023-1112Kavram kanıtı | Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversalcodedropz · drag and drop multiple file upload - contact form 7 · CWE-23 | Kritik9,8 | — | %3,0 | 1 Mar 2023 |
40Planlayın | CVE-2023-5822İstismar yok | Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Uploadcodedropz · drag and drop multiple file upload - contact form 7 · CWE-434 | Kritik9,8 | — | %1,8 | 22 Kas 2023 |
39İzleyin | CVE-2022-45377İstismar yok | WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilitiescodedropz · drag and drop multiple file upload for woocommerce · CWE-434 | Kritik9,8 | — | %0,6 | 21 Ara 2023 |
36İzleyin | CVE-2024-12267İstismar yok | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletioncodedropz · drag and drop multiple file upload - contact form 7 · CWE-73 | Kritik9,1 | — | %0,3 | 31 Oca 2025 |
35İzleyin | CVE-2025-2328İstismar yok | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletioncodedropz · drag and drop multiple file upload - contact form 7 · CWE-22 | Yüksek8,8 | — | %1,1 | 28 Mar 2025 |
35İzleyin | CVE-2025-2485İstismar yok | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletioncodedropz · drag and drop multiple file upload - contact form 7 · CWE-502 | Yüksek8,8 | — | %0,6 | 28 Mar 2025 |
35İzleyin | CVE-2022-45364İstismar yok | WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)codedropz · drag and drop multiple file upload - contact form 7 · CWE-352 | Yüksek8,8 | — | %0,2 | 24 May 2023 |
30İzleyin | CVE-2024-3717İstismar yok | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposurecodedropz · drag and drop multiple file upload - contact form 7 · CWE-922 | Yüksek7,5 | — | %0,7 | 2 May 2024 |
29İzleyin | CVE-2025-14457İstismar yok | Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletioncodedropz · contact form 7 · CWE-862 | Yüksek7,4 | — | %0,2 | 15 Oca 2026 |
25İzleyin | CVE-2022-0595Kavram kanıtı | Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSScodedropz · drag and drop multiple file upload - contact form 7 · CWE-79 | Orta5,4 | — | %13,6 | 28 Mar 2022 |
24İzleyin | CVE-2023-1282İstismar yok | Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scriptingcodedropz · drag and drop multiple file upload - contact form 7 · CWE-79 | Orta6,1 | — | %0,5 | 17 Nis 2023 |
21İzleyin | CVE-2023-4821İstismar yok | Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scriptingcodedropz · drag and drop multiple file uploader · CWE-79 | Orta5,4 | — | %0,4 | 16 Eki 2023 |
17İzleyin | CVE-2022-3282İstismar yok | Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypasscodedropz · drag and drop multiple file upload - contact form 7 · CWE-639 | Orta4,3 | — | %0,6 | 17 Eki 2022 |
- CVE-2020-1280063Bu hafta
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code ex
KritikCVSS 9,8SilahlaştırılmışEPSS %79codedropz · drag and drop multiple file upload - contact form 78 Haz 2020
- CVE-2025-351541Planlayın
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
KritikCVSS 9,8Kavram kanıtıEPSS %6codedropz · drag and drop multiple file upload - contact form 717 Haz 2025
- CVE-2023-111240Planlayın
Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal
KritikCVSS 9,8Kavram kanıtıEPSS %3codedropz · drag and drop multiple file upload - contact form 71 Mar 2023
- CVE-2023-582240Planlayın
Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload
KritikCVSS 9,8İstismar yokEPSS %2codedropz · drag and drop multiple file upload - contact form 722 Kas 2023
- CVE-2022-4537739İzleyin
WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %1codedropz · drag and drop multiple file upload for woocommerce21 Ara 2023
- CVE-2024-1226736İzleyin
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion
KritikCVSS 9,1İstismar yokEPSS %0codedropz · drag and drop multiple file upload - contact form 731 Oca 2025
- CVE-2025-232835İzleyin
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion
YüksekCVSS 8,8İstismar yokEPSS %1codedropz · drag and drop multiple file upload - contact form 728 Mar 2025
- CVE-2025-248535İzleyin
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion
YüksekCVSS 8,8İstismar yokEPSS %1codedropz · drag and drop multiple file upload - contact form 728 Mar 2025
- CVE-2022-4536435İzleyin
WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0codedropz · drag and drop multiple file upload - contact form 724 May 2023
- CVE-2024-371730İzleyin
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure
YüksekCVSS 7,5İstismar yokEPSS %1codedropz · drag and drop multiple file upload - contact form 72 May 2024
- CVE-2025-1445729İzleyin
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion
YüksekCVSS 7,4İstismar yokEPSS %0codedropz · contact form 715 Oca 2026
- CVE-2022-059525İzleyin
Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS
OrtaCVSS 5,4Kavram kanıtıEPSS %14codedropz · drag and drop multiple file upload - contact form 728 Mar 2022
- CVE-2023-128224İzleyin
Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1codedropz · drag and drop multiple file upload - contact form 717 Nis 2023
- CVE-2023-482121İzleyin
Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0codedropz · drag and drop multiple file uploader16 Eki 2023
- CVE-2022-328217İzleyin
Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass
OrtaCVSS 4,3İstismar yokEPSS %1codedropz · drag and drop multiple file upload - contact form 717 Eki 2022