Etoilewebdesign kayıtları
etoilewebdesign üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %23,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-306 Missing Authentication for Critical Function1
- CWE-502 Deserialization of Untrusted Data1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2025-2005Kavram kanıtı | Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Uploadetoilewebdesign · front end users · CWE-434 | Kritik9,8 | — | %22,0 | 2 Nis 2025 |
40Planlayın | CVE-2017-12199İstismar yok | The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogueetoilewebdesign · ultimate product catalog · CWE-89 | Kritik9,8 | — | %1,8 | 2 Ağu 2017 |
39İzleyin | CVE-2020-36726İstismar yok | Ultimate Reviews < 2.1.33 - PHP Object Injectionetoilewebdesign · ultimate reviews · CWE-502 | Kritik9,8 | — | %1,6 | 6 Haz 2023 |
39İzleyin | CVE-2025-47580İstismar yok | WordPress Front End Users plugin <= 3.2.35 - Broken Access Control vulnerabilityetoilewebdesign · front end users · CWE-862 | Kritik9,8 | — | %0,3 | 15 May 2025 |
35İzleyin | CVE-2024-7607İstismar yok | Front End Users <= 3.2.28 - Authenticated (Contributor+) Time-Based SQL Injectionetoilewebdesign · front end users · CWE-89 | Yüksek8,8 | — | %0,5 | 29 Ağu 2024 |
35İzleyin | CVE-2024-43343İstismar yok | WordPress Order Tracking – WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control vulnerabilityetoilewebdesign · order tracking · CWE-862 | Yüksek8,8 | — | %0,5 | 1 Kas 2024 |
35İzleyin | CVE-2023-34005İstismar yok | WordPress Front End Users Plugin <= 3.2.24 is vulnerable to Cross Site Request Forgery (CSRF)etoilewebdesign · front end users · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Tem 2023 |
31İzleyin | CVE-2019-17232Kavram kanıtı | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.etoilewebdesign · ultimate faq · CWE-306 | Yüksek7,5 | — | %3,5 | 7 Eki 2019 |
28İzleyin | CVE-2024-13569Kavram kanıtı | Front End Users <= 3.2.32 - Reflected XSSetoilewebdesign · front end users · CWE-79 | Yüksek7,1 | — | %0,5 | 22 Nis 2025 |
26İzleyin | CVE-2021-24993İstismar yok | Ultimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Updateetoilewebdesign · ultimate product catalog · CWE-862 | Orta6,5 | — | %0,5 | 7 Şub 2022 |
25İzleyin | CVE-2020-7107Kavram kanıtı | The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.etoilewebdesign · ultimate faq · CWE-79 | Orta6,1 | — | %2,2 | 16 Oca 2020 |
25İzleyin | CVE-2019-17233Kavram kanıtı | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.etoilewebdesign · ultimate faq · CWE-79 | Orta6,1 | — | %1,8 | 7 Eki 2019 |
24İzleyin | CVE-2020-24313İstismar yok | Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointmenetoilewebdesign · ultimate appointment booking \& scheduling · CWE-79 | Orta6,1 | — | %1,2 | 26 Ağu 2020 |
24İzleyin | CVE-2019-15643İstismar yok | The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.etoilewebdesign · ultimate faq · CWE-79 | Orta6,1 | — | %0,9 | 27 Ağu 2019 |
24İzleyin | CVE-2017-12200İstismar yok | The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.etoilewebdesign · ultimate product catalog · CWE-79 | Orta6,1 | — | %0,9 | 2 Ağu 2017 |
24İzleyin | CVE-2023-4471İstismar yok | Order Tracking Pro <= 3.3.6 - Reflected Cross-Site Scriptingetoilewebdesign · order tracking · CWE-79 | Orta6,1 | — | %0,6 | 31 Ağu 2023 |
24İzleyin | CVE-2023-33322İstismar yok | WordPress Front End Users plugin < 3.2.25 - Cross Site Scripting (XSS) vulnerabilityetoilewebdesign · front end users · CWE-79 | Orta6,1 | — | %0,4 | 26 Mar 2024 |
24İzleyin | CVE-2024-25597İstismar yok | WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerabilityetoilewebdesign · ultimate reviews · CWE-79 | Orta6,1 | — | %0,4 | 15 Mar 2024 |
22İzleyin | CVE-2021-24968İstismar yok | Ultimate FAQ < 2.1.2 - Subscriber+ Arbitrary FAQ Creationetoilewebdesign · ultimate faq · CWE-862 | Orta5,7 | — | %0,4 | 24 Oca 2022 |
21İzleyin | CVE-2024-7606İstismar yok | Front End Users <= 3.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeetoilewebdesign · front end users · CWE-79 | Orta5,4 | — | %0,3 | 29 Ağu 2024 |
21İzleyin | CVE-2024-13563İstismar yok | Front End Users <= 3.2.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via forgot-password Shortcodeetoilewebdesign · front end users · CWE-79 | Orta5,4 | — | %0,3 | 15 Şub 2025 |
21İzleyin | CVE-2025-26877İstismar yok | WordPress Front End Users Plugin <= 3.2.30 - Cross Site Scripting (XSS) vulnerabilityetoilewebdesign · front end users · CWE-79 | Orta5,4 | — | %0,3 | 25 Şub 2025 |
19İzleyin | CVE-2022-23979İstismar yok | WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityetoilewebdesign · ultimate reviews · CWE-79 | Orta4,8 | — | %0,6 | 28 Oca 2022 |
19İzleyin | CVE-2023-2711İstismar yok | Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSSetoilewebdesign · ultimate product catalog · CWE-79 | Orta4,8 | — | %0,5 | 27 Haz 2023 |
19İzleyin | CVE-2024-12410İstismar yok | Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injectionetoilewebdesign · front end users · CWE-89 | Orta4,9 | — | %0,4 | 2 Nis 2025 |
- CVE-2025-200546Planlayın
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
KritikCVSS 9,8Kavram kanıtıEPSS %22etoilewebdesign · front end users2 Nis 2025
- CVE-2017-1219940Planlayın
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue
KritikCVSS 9,8İstismar yokEPSS %2etoilewebdesign · ultimate product catalog2 Ağu 2017
- CVE-2020-3672639İzleyin
Ultimate Reviews < 2.1.33 - PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %2etoilewebdesign · ultimate reviews6 Haz 2023
- CVE-2025-4758039İzleyin
WordPress Front End Users plugin <= 3.2.35 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0etoilewebdesign · front end users15 May 2025
- CVE-2024-760735İzleyin
Front End Users <= 3.2.28 - Authenticated (Contributor+) Time-Based SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1etoilewebdesign · front end users29 Ağu 2024
- CVE-2024-4334335İzleyin
WordPress Order Tracking – WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0etoilewebdesign · order tracking1 Kas 2024
- CVE-2023-3400535İzleyin
WordPress Front End Users Plugin <= 3.2.24 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0etoilewebdesign · front end users17 Tem 2023
- CVE-2019-1723231İzleyin
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
YüksekCVSS 7,5Kavram kanıtıEPSS %4etoilewebdesign · ultimate faq7 Eki 2019
- CVE-2024-1356928İzleyin
Front End Users <= 3.2.32 - Reflected XSS
YüksekCVSS 7,1Kavram kanıtıEPSS %1etoilewebdesign · front end users22 Nis 2025
- CVE-2021-2499326İzleyin
Ultimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Update
OrtaCVSS 6,5İstismar yokEPSS %0etoilewebdesign · ultimate product catalog7 Şub 2022
- CVE-2020-710725İzleyin
The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.
OrtaCVSS 6,1Kavram kanıtıEPSS %2etoilewebdesign · ultimate faq16 Oca 2020
- CVE-2019-1723325İzleyin
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
OrtaCVSS 6,1Kavram kanıtıEPSS %2etoilewebdesign · ultimate faq7 Eki 2019
- CVE-2020-2431324İzleyin
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointmen
OrtaCVSS 6,1İstismar yokEPSS %1etoilewebdesign · ultimate appointment booking \& scheduling26 Ağu 2020
- CVE-2019-1564324İzleyin
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1etoilewebdesign · ultimate faq27 Ağu 2019
- CVE-2017-1220024İzleyin
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.
OrtaCVSS 6,1İstismar yokEPSS %1etoilewebdesign · ultimate product catalog2 Ağu 2017
- CVE-2023-447124İzleyin
Order Tracking Pro <= 3.3.6 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1etoilewebdesign · order tracking31 Ağu 2023
- CVE-2023-3332224İzleyin
WordPress Front End Users plugin < 3.2.25 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0etoilewebdesign · front end users26 Mar 2024
- CVE-2024-2559724İzleyin
WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0etoilewebdesign · ultimate reviews15 Mar 2024
- CVE-2021-2496822İzleyin
Ultimate FAQ < 2.1.2 - Subscriber+ Arbitrary FAQ Creation
OrtaCVSS 5,7İstismar yokEPSS %0etoilewebdesign · ultimate faq24 Oca 2022
- CVE-2024-760621İzleyin
Front End Users <= 3.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0etoilewebdesign · front end users29 Ağu 2024
- CVE-2024-1356321İzleyin
Front End Users <= 3.2.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via forgot-password Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0etoilewebdesign · front end users15 Şub 2025
- CVE-2025-2687721İzleyin
WordPress Front End Users Plugin <= 3.2.30 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0etoilewebdesign · front end users25 Şub 2025
- CVE-2022-2397919İzleyin
WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
OrtaCVSS 4,8İstismar yokEPSS %1etoilewebdesign · ultimate reviews28 Oca 2022
- CVE-2023-271119İzleyin
Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %1etoilewebdesign · ultimate product catalog27 Haz 2023
- CVE-2024-1241019İzleyin
Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injection
OrtaCVSS 4,9İstismar yokEPSS %0etoilewebdesign · front end users2 Nis 2025