gVectors kayıtları
gvectors üreticisine ait 70 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %1,4
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %21,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-352 Cross-Site Request Forgery (CSRF)10
- CWE-639 Authorization Bypass Through User-Controlled Key7
- CWE-862 Missing Authorization7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
70 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2020-24186Silahlaştırılmış | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated ugvectors · wpdiscuz · CWE-434 | Kritik10,0 | — | %94,6 | 24 Ağu 2020 |
53Planlayın | CVE-2023-2249İstismar yok | wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contentsgvectors · wpforo forum · CWE-98 | Yüksek8,8 | — | %60,8 | 9 Haz 2023 |
43Planlayın | CVE-2020-13640Kavram kanıtı | A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commagvectors · wpdiscuz · CWE-89 | Kritik9,8 | — | %12,6 | 18 Haz 2020 |
40Planlayın | CVE-2018-16613İstismar yok | An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress.gvectors · wpforo forum | Kritik9,8 | — | %2,7 | 19 Haz 2019 |
39İzleyin | CVE-2018-11515İstismar yok | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.gvectors · wpforo · CWE-89 | Kritik9,8 | — | %1,7 | 28 May 2018 |
39İzleyin | CVE-2024-9488İstismar yok | Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth providergvectors · wpdiscuz · CWE-288 | Kritik9,8 | — | %0,8 | 25 Eki 2024 |
39İzleyin | CVE-2023-47868İstismar yok | WordPress wpForo plugin <= 2.2.3 - Privilege Escalation vulnerabilitygvectors · wpforo forum · CWE-269 | Kritik9,8 | — | %0,5 | 17 May 2024 |
36İzleyin | CVE-2026-22193İstismar yok | wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()gvectors · wpdiscuz · CWE-89 | Kritik9,2 | — | %0,3 | 13 Mar 2026 |
35İzleyin | CVE-2022-40200İstismar yok | WordPress wpForo Forum plugin <= 2.0.9 - Auth. Arbitrary File Upload vulnerabilitygvectors · wpforo forum · CWE-434 | Yüksek8,8 | — | %1,0 | 17 Kas 2022 |
35İzleyin | CVE-2019-19109İstismar yok | The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.gvectors · wpforo · CWE-352 | Yüksek8,8 | — | %0,7 | 15 Haz 2020 |
35İzleyin | CVE-2022-43492İstismar yok | WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerabilitygvectors · wpdiscuz · CWE-639 | Yüksek8,8 | — | %0,7 | 18 Kas 2022 |
35İzleyin | CVE-2026-28562İstismar yok | wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parametergvectors · wpforo forum · CWE-89 | Yüksek8,8 | — | %0,5 | 28 Şub 2026 |
35İzleyin | CVE-2022-38144İstismar yok | WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerabilitygvectors · wpforo forum · CWE-352 | Yüksek8,8 | — | %0,5 | 9 Eyl 2022 |
35İzleyin | CVE-2022-40192İstismar yok | WordPress wpForo Forum plugin <= 2.0.9 - Cross-Site Request Forgery (CSRF) vulnerabilitygvectors · wpforo forum · CWE-352 | Yüksek8,8 | — | %0,5 | 17 Kas 2022 |
35İzleyin | CVE-2023-45760İstismar yok | WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerabilitygvectors · wpdiscuz · CWE-862 | Yüksek8,8 | — | %0,4 | 2 Oca 2025 |
35İzleyin | CVE-2023-49759İstismar yok | WordPress WooDiscuz – WooCommerce Comments Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)gvectors · woodiscuz - woocommerce comments · CWE-352 | Yüksek8,8 | — | %0,3 | 18 Ara 2023 |
35İzleyin | CVE-2026-22192İstismar yok | Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStoragegvectors · wpdiscuz · CWE-306 | Yüksek8,8 | — | %0,3 | 13 Mar 2026 |
35İzleyin | CVE-2023-47870İstismar yok | WordPress wpForo Forum Plugin <= 2.2.6 is vulnerable to Broken Access Control and Cross Site Request Forgery (CSRF)gvectors · wpforo forum · CWE-352 | Yüksek8,8 | — | %0,3 | 30 Kas 2023 |
35İzleyin | CVE-2023-47775İstismar yok | WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)gvectors · wpdiscuz · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Kas 2023 |
34İzleyin | CVE-2026-22199İstismar yok | Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgigvectors · wpdiscuz · CWE-22 | Yüksek8,7 | — | %1,0 | 13 Mar 2026 |
34İzleyin | CVE-2026-22182İstismar yok | wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationTypegvectors · wpdiscuz · CWE-862 | Yüksek8,7 | — | %0,5 | 13 Mar 2026 |
32İzleyin | CVE-2024-43288İstismar yok | WordPress wpForo Forum plugin <= 2.3.4 - Insecure Direct Object References (IDOR) vulnerabilitygvectors · wpforo forum · CWE-639 | Yüksek8,1 | — | %0,3 | 18 Ağu 2024 |
30İzleyin | CVE-2022-23984İstismar yok | WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosuregvectors · wpdiscuz · CWE-200 | Yüksek7,5 | — | %1,1 | 21 Şub 2022 |
30İzleyin | CVE-2024-43289İstismar yok | WordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerabilitygvectors · wpforo forum · CWE-200 | Yüksek7,5 | — | %0,4 | 26 Ağu 2024 |
29İzleyin | CVE-2023-46309İstismar yok | WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerabilitygvectors · wpdiscuz · CWE-862 | Yüksek7,3 | — | %0,4 | 2 Oca 2025 |
- CVE-2020-2418668Bu hafta
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated u
KritikCVSS 10,0SilahlaştırılmışEPSS %95gvectors · wpdiscuz24 Ağu 2020
- CVE-2023-224953Planlayın
wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents
YüksekCVSS 8,8İstismar yokEPSS %61gvectors · wpforo forum9 Haz 2023
- CVE-2020-1364043Planlayın
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL comma
KritikCVSS 9,8Kavram kanıtıEPSS %13gvectors · wpdiscuz18 Haz 2020
- CVE-2018-1661340Planlayın
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress.
KritikCVSS 9,8İstismar yokEPSS %3gvectors · wpforo forum19 Haz 2019
- CVE-2018-1151539İzleyin
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
KritikCVSS 9,8İstismar yokEPSS %2gvectors · wpforo28 May 2018
- CVE-2024-948839İzleyin
Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider
KritikCVSS 9,8İstismar yokEPSS %1gvectors · wpdiscuz25 Eki 2024
- CVE-2023-4786839İzleyin
WordPress wpForo plugin <= 2.2.3 - Privilege Escalation vulnerability
KritikCVSS 9,8İstismar yokEPSS %0gvectors · wpforo forum17 May 2024
- CVE-2026-2219336İzleyin
wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()
KritikCVSS 9,2İstismar yokEPSS %0gvectors · wpdiscuz13 Mar 2026
- CVE-2022-4020035İzleyin
WordPress wpForo Forum plugin <= 2.0.9 - Auth. Arbitrary File Upload vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1gvectors · wpforo forum17 Kas 2022
- CVE-2019-1910935İzleyin
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1gvectors · wpforo15 Haz 2020
- CVE-2022-4349235İzleyin
WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1gvectors · wpdiscuz18 Kas 2022
- CVE-2026-2856235İzleyin
wpForo Forum 2.4.14 SQL Injection via Topics ORDER BY Parameter
YüksekCVSS 8,8İstismar yokEPSS %1gvectors · wpforo forum28 Şub 2026
- CVE-2022-3814435İzleyin
WordPress wpForo Forum plugin <= 2.0.5 - Cross-Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1gvectors · wpforo forum9 Eyl 2022
- CVE-2022-4019235İzleyin
WordPress wpForo Forum plugin <= 2.0.9 - Cross-Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0gvectors · wpforo forum17 Kas 2022
- CVE-2023-4576035İzleyin
WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0gvectors · wpdiscuz2 Oca 2025
- CVE-2023-4975935İzleyin
WordPress WooDiscuz – WooCommerce Comments Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0gvectors · woodiscuz - woocommerce comments18 Ara 2023
- CVE-2026-2219235İzleyin
Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage
YüksekCVSS 8,8İstismar yokEPSS %0gvectors · wpdiscuz13 Mar 2026
- CVE-2023-4787035İzleyin
WordPress wpForo Forum Plugin <= 2.2.6 is vulnerable to Broken Access Control and Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0gvectors · wpforo forum30 Kas 2023
- CVE-2023-4777535İzleyin
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0gvectors · wpdiscuz22 Kas 2023
- CVE-2026-2219934İzleyin
Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi
YüksekCVSS 8,7İstismar yokEPSS %1gvectors · wpdiscuz13 Mar 2026
- CVE-2026-2218234İzleyin
wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType
YüksekCVSS 8,7İstismar yokEPSS %1gvectors · wpdiscuz13 Mar 2026
- CVE-2024-4328832İzleyin
WordPress wpForo Forum plugin <= 2.3.4 - Insecure Direct Object References (IDOR) vulnerability
YüksekCVSS 8,1İstismar yokEPSS %0gvectors · wpforo forum18 Ağu 2024
- CVE-2022-2398430İzleyin
WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %1gvectors · wpdiscuz21 Şub 2022
- CVE-2024-4328930İzleyin
WordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0gvectors · wpforo forum26 Ağu 2024
- CVE-2023-4630929İzleyin
WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability
YüksekCVSS 7,3İstismar yokEPSS %0gvectors · wpdiscuz2 Oca 2025