iThemes kayıtları
ithemes üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-287 Improper Authentication3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-532 Insertion of Sensitive Information into Log File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2020-14092Kavram kanıtı | The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.ithemes · paypal pro · CWE-89 | Kritik9,8 | — | %94,5 | 2 Tem 2020 |
49Planlayın | CVE-2022-31474Kavram kanıtı | WordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversalithemes · backupbuddy · CWE-22 | Yüksek7,5 | — | %63,8 | 13 Mar 2023 |
37İzleyin | CVE-2018-12636Kavram kanıtı | The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via thithemes · security · CWE-89 | Yüksek7,2 | — | %29,8 | 22 Haz 2018 |
31İzleyin | CVE-2013-2743İstismar yok | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authenticawordpress · wordpress · CWE-287 | Yüksek7,5 | — | %2,6 | 2 Nis 2013 |
31İzleyin | CVE-2013-2741İstismar yok | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabwordpress · wordpress · CWE-287 | Yüksek7,5 | — | %2,6 | 2 Nis 2013 |
31İzleyin | CVE-2013-2742İstismar yok | importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after complewordpress · wordpress | Yüksek7,5 | — | %2,4 | 2 Nis 2013 |
30İzleyin | CVE-2018-7433İstismar yok | The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.ithemes · security · CWE-532 | Yüksek7,5 | — | %1,4 | 2 Mar 2018 |
30İzleyin | CVE-2020-36176İstismar yok | The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an exisithemes · ithemes security · CWE-287 | Yüksek7,5 | — | %1,3 | 6 Oca 2021 |
24İzleyin | CVE-2015-9371İstismar yok | Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · manual purchases · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9374İstismar yok | Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · stripe · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9375İstismar yok | Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · table rate shipping · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9376İstismar yok | iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · mobile · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9377İstismar yok | iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · builder theme depot · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9378İstismar yok | iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · builder theme market · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9379İstismar yok | iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · builder style manager · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9372İstismar yok | Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · membership · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9363İstismar yok | iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · exchange · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9365İstismar yok | Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · authorize.net · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9366İstismar yok | Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · custom url tracking · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9367İstismar yok | Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · easy canadian sales taxes · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9368İstismar yok | Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · easy eu value added \(vat\) taxes · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9369İstismar yok | Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · easy us sales taxes · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2015-9370İstismar yok | Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().ithemes · invoices · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2022-4897Kavram kanıtı | BackupBuddy < 8.8.3 - Multiple Reflected Cross-Site Scriptingithemes · backupbuddy · CWE-79 | Orta6,1 | — | %0,9 | 21 Şub 2023 |
21İzleyin | CVE-2013-2744İstismar yok | importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpiwordpress · wordpress · CWE-200 | Orta5,0 | — | %2,1 | 2 Nis 2013 |
- CVE-2020-1409267Bu hafta
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
KritikCVSS 9,8Kavram kanıtıEPSS %95ithemes · paypal pro2 Tem 2020
- CVE-2022-3147449Planlayın
WordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversal
YüksekCVSS 7,5Kavram kanıtıEPSS %64ithemes · backupbuddy13 Mar 2023
- CVE-2018-1263637İzleyin
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via th
YüksekCVSS 7,2Kavram kanıtıEPSS %30ithemes · security22 Haz 2018
- CVE-2013-274331İzleyin
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentica
YüksekCVSS 7,5İstismar yokEPSS %3wordpress · wordpress2 Nis 2013
- CVE-2013-274131İzleyin
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enab
YüksekCVSS 7,5İstismar yokEPSS %3wordpress · wordpress2 Nis 2013
- CVE-2013-274231İzleyin
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after comple
YüksekCVSS 7,5İstismar yokEPSS %2wordpress · wordpress2 Nis 2013
- CVE-2018-743330İzleyin
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
YüksekCVSS 7,5İstismar yokEPSS %1ithemes · security2 Mar 2018
- CVE-2020-3617630İzleyin
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an exis
YüksekCVSS 7,5İstismar yokEPSS %1ithemes · ithemes security6 Oca 2021
- CVE-2015-937124İzleyin
Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · manual purchases28 Ağu 2019
- CVE-2015-937424İzleyin
Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · stripe28 Ağu 2019
- CVE-2015-937524İzleyin
Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · table rate shipping28 Ağu 2019
- CVE-2015-937624İzleyin
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · mobile28 Ağu 2019
- CVE-2015-937724İzleyin
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · builder theme depot28 Ağu 2019
- CVE-2015-937824İzleyin
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · builder theme market28 Ağu 2019
- CVE-2015-937924İzleyin
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · builder style manager28 Ağu 2019
- CVE-2015-937224İzleyin
Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · membership28 Ağu 2019
- CVE-2015-936324İzleyin
iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · exchange28 Ağu 2019
- CVE-2015-936524İzleyin
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · authorize.net28 Ağu 2019
- CVE-2015-936624İzleyin
Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · custom url tracking28 Ağu 2019
- CVE-2015-936724İzleyin
Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · easy canadian sales taxes28 Ağu 2019
- CVE-2015-936824İzleyin
Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · easy eu value added \(vat\) taxes28 Ağu 2019
- CVE-2015-936924İzleyin
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · easy us sales taxes28 Ağu 2019
- CVE-2015-937024İzleyin
Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1ithemes · invoices28 Ağu 2019
- CVE-2022-489724İzleyin
BackupBuddy < 8.8.3 - Multiple Reflected Cross-Site Scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %1ithemes · backupbuddy21 Şub 2023
- CVE-2013-274421İzleyin
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpi
OrtaCVSS 5,0İstismar yokEPSS %2wordpress · wordpress2 Nis 2013