Dev4Press kayıtları
dev4press üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2024-0852İstismar yok | coreActivity < 1.8.1 - Unauthenticated Stored XSSdev4press · coreactivity · CWE-79 | Yüksek8,8 | — | %0,7 | 15 May 2025 |
30İzleyin | CVE-2014-2839İstismar yok | SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands dev4press · gd star rating · CWE-89 | Yüksek7,5 | — | %1,6 | 12 Oca 2015 |
28İzleyin | CVE-2023-46821İstismar yok | WordPress GD Security Headers Plugin <= 1.7 is vulnerable to SQL Injectiondev4press · gd security headers · CWE-89 | Yüksek7,2 | — | %0,6 | 6 Kas 2023 |
27İzleyin | CVE-2014-2838İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijackdev4press · gd star rating · CWE-352 | Orta6,8 | — | %1,0 | 12 Oca 2015 |
24İzleyin | CVE-2017-18591İstismar yok | The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.dev4press · gd rating system · CWE-79 | Orta6,1 | — | %0,9 | 27 Ağu 2019 |
24İzleyin | CVE-2023-3122İstismar yok | GD Mail Queue <= 3.9.3 - Unauthenticated Stored Cross-Site Scripting via Emaildev4press · gd mail queue · CWE-79 | Orta6,1 | — | %0,5 | 12 Tem 2023 |
24İzleyin | CVE-2024-25093İstismar yok | WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS)dev4press · gd rating system · CWE-79 | Orta6,1 | — | %0,4 | 29 Şub 2024 |
24İzleyin | CVE-2023-40330İstismar yok | WordPress GD Security Headers Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)dev4press · gd security headers · CWE-79 | Orta6,1 | — | %0,4 | 27 Eyl 2023 |
21İzleyin | CVE-2024-0868İstismar yok | coreActivity < 2.1 - Unauthenticated IP Spoofingdev4press · coreactivity · CWE-290 | Orta5,3 | — | %0,5 | 17 Nis 2024 |
21İzleyin | CVE-2022-45816İstismar yok | WordPress GD bbPress Attachments Plugin <= 4.3.1 is vulnerable to Cross Site Scripting (XSS)dev4press · gd bbpress attachments · CWE-79 | Orta5,4 | — | %0,4 | 6 Ara 2022 |
18İzleyin | CVE-2015-5481İstismar yok | Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attdev4press · gd bbpress attachments · CWE-79 | Orta4,3 | — | %2,1 | 18 Ağu 2015 |
17İzleyin | CVE-2015-5482İstismar yok | Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and dev4press · gd bbpress attachments · CWE-22 | Orta4,0 | — | %1,8 | 18 Ağu 2015 |
- CVE-2024-085235İzleyin
coreActivity < 1.8.1 - Unauthenticated Stored XSS
YüksekCVSS 8,8İstismar yokEPSS %1dev4press · coreactivity15 May 2025
- CVE-2014-283930İzleyin
SQL injection vulnerability in the GD Star Rating plugin 19.22 for WordPress allows remote administrators to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %2dev4press · gd star rating12 Oca 2015
- CVE-2023-4682128İzleyin
WordPress GD Security Headers Plugin <= 1.7 is vulnerable to SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1dev4press · gd security headers6 Kas 2023
- CVE-2014-283827İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the GD Star Rating plugin 19.22 for WordPress allow remote attackers to hijack
OrtaCVSS 6,8İstismar yokEPSS %1dev4press · gd star rating12 Oca 2015
- CVE-2017-1859124İzleyin
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
OrtaCVSS 6,1İstismar yokEPSS %1dev4press · gd rating system27 Ağu 2019
- CVE-2023-312224İzleyin
GD Mail Queue <= 3.9.3 - Unauthenticated Stored Cross-Site Scripting via Email
OrtaCVSS 6,1İstismar yokEPSS %0dev4press · gd mail queue12 Tem 2023
- CVE-2024-2509324İzleyin
WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0dev4press · gd rating system29 Şub 2024
- CVE-2023-4033024İzleyin
WordPress GD Security Headers Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0dev4press · gd security headers27 Eyl 2023
- CVE-2024-086821İzleyin
coreActivity < 2.1 - Unauthenticated IP Spoofing
OrtaCVSS 5,3İstismar yokEPSS %0dev4press · coreactivity17 Nis 2024
- CVE-2022-4581621İzleyin
WordPress GD bbPress Attachments Plugin <= 4.3.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0dev4press · gd bbpress attachments6 Ara 2022
- CVE-2015-548118İzleyin
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote att
OrtaCVSS 4,3İstismar yokEPSS %2dev4press · gd bbpress attachments18 Ağu 2015
- CVE-2015-548217İzleyin
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and
OrtaCVSS 4,0İstismar yokEPSS %2dev4press · gd bbpress attachments18 Ağu 2015