İçeriğe atla
Noroxi

Etoilewebdesign kayıtları

etoilewebdesign üreticisine ait 26 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%23,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

26 kayıt
  • CVE-2025-2005
    46Planlayın

    Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload

    KritikCVSS 9,8Kavram kanıtıEPSS %22

    etoilewebdesign · front end users2 Nis 2025

  • CVE-2017-12199
    40Planlayın

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue

    KritikCVSS 9,8İstismar yokEPSS %2

    etoilewebdesign · ultimate product catalog2 Ağu 2017

  • CVE-2020-36726
    39İzleyin

    Ultimate Reviews < 2.1.33 - PHP Object Injection

    KritikCVSS 9,8İstismar yokEPSS %2

    etoilewebdesign · ultimate reviews6 Haz 2023

  • CVE-2025-47580
    39İzleyin

    WordPress Front End Users plugin <= 3.2.35 - Broken Access Control vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    etoilewebdesign · front end users15 May 2025

  • CVE-2024-7607
    35İzleyin

    Front End Users <= 3.2.28 - Authenticated (Contributor+) Time-Based SQL Injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    etoilewebdesign · front end users29 Ağu 2024

  • CVE-2024-43343
    35İzleyin

    WordPress Order Tracking – WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    etoilewebdesign · order tracking1 Kas 2024

  • CVE-2023-34005
    35İzleyin

    WordPress Front End Users Plugin <= 3.2.24 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    etoilewebdesign · front end users17 Tem 2023

  • CVE-2019-17232
    31İzleyin

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    etoilewebdesign · ultimate faq7 Eki 2019

  • CVE-2024-13569
    28İzleyin

    Front End Users <= 3.2.32 - Reflected XSS

    YüksekCVSS 7,1Kavram kanıtıEPSS %1

    etoilewebdesign · front end users22 Nis 2025

  • CVE-2021-24993
    26İzleyin

    Ultimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Update

    OrtaCVSS 6,5İstismar yokEPSS %0

    etoilewebdesign · ultimate product catalog7 Şub 2022

  • CVE-2020-7107
    25İzleyin

    The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    etoilewebdesign · ultimate faq16 Oca 2020

  • CVE-2019-17233
    25İzleyin

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    etoilewebdesign · ultimate faq7 Eki 2019

  • CVE-2020-24313
    24İzleyin

    Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointmen

    OrtaCVSS 6,1İstismar yokEPSS %1

    etoilewebdesign · ultimate appointment booking \& scheduling26 Ağu 2020

  • CVE-2019-15643
    24İzleyin

    The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    etoilewebdesign · ultimate faq27 Ağu 2019

  • CVE-2017-12200
    24İzleyin

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

    OrtaCVSS 6,1İstismar yokEPSS %1

    etoilewebdesign · ultimate product catalog2 Ağu 2017

  • CVE-2023-4471
    24İzleyin

    Order Tracking Pro <= 3.3.6 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    etoilewebdesign · order tracking31 Ağu 2023

  • CVE-2023-33322
    24İzleyin

    WordPress Front End Users plugin < 3.2.25 - Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %0

    etoilewebdesign · front end users26 Mar 2024

  • CVE-2024-25597
    24İzleyin

    WordPress Ultimate Reviews plugin <= 3.2.8 - Unauthenticated Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %0

    etoilewebdesign · ultimate reviews15 Mar 2024

  • CVE-2021-24968
    22İzleyin

    Ultimate FAQ < 2.1.2 - Subscriber+ Arbitrary FAQ Creation

    OrtaCVSS 5,7İstismar yokEPSS %0

    etoilewebdesign · ultimate faq24 Oca 2022

  • CVE-2024-7606
    21İzleyin

    Front End Users <= 3.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %0

    etoilewebdesign · front end users29 Ağu 2024

  • CVE-2024-13563
    21İzleyin

    Front End Users <= 3.2.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via forgot-password Shortcode

    OrtaCVSS 5,4İstismar yokEPSS %0

    etoilewebdesign · front end users15 Şub 2025

  • CVE-2025-26877
    21İzleyin

    WordPress Front End Users Plugin <= 3.2.30 - Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 5,4İstismar yokEPSS %0

    etoilewebdesign · front end users25 Şub 2025

  • CVE-2022-23979
    19İzleyin

    WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

    OrtaCVSS 4,8İstismar yokEPSS %1

    etoilewebdesign · ultimate reviews28 Oca 2022

  • CVE-2023-2711
    19İzleyin

    Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSS

    OrtaCVSS 4,8İstismar yokEPSS %1

    etoilewebdesign · ultimate product catalog27 Haz 2023

  • CVE-2024-12410
    19İzleyin

    Front End Users <= 3.2.32 - Authenticated (Admin+) SQL injection

    OrtaCVSS 4,9İstismar yokEPSS %0

    etoilewebdesign · front end users2 Nis 2025