LiquidWeb kayıtları
liquidweb üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %45,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2019-16120İstismar yok | CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Expoliquidweb · event tickets · CWE-1236 | Yüksek8,8 | — | %3,2 | 8 Eyl 2019 |
30İzleyin | CVE-2023-47668Kavram kanıtı | WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposureliquidweb · restrict content · CWE-200 | Yüksek7,5 | — | %1,0 | 22 Kas 2023 |
30İzleyin | CVE-2025-14844İstismar yok | Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposureliquidweb · restrict content · CWE-639 | Yüksek7,5 | — | %0,5 | 16 Oca 2026 |
30İzleyin | CVE-2024-11090İstismar yok | Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposureliquidweb · restrict content · CWE-200 | Yüksek7,5 | — | %0,5 | 26 Oca 2025 |
26İzleyin | CVE-2024-1316İstismar yok | Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Accessliquidweb · event tickets · CWE-284 | Orta6,5 | — | %0,6 | 4 Mar 2024 |
24İzleyin | CVE-2022-45825İstismar yok | WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)liquidweb · wpcomplete · CWE-79 | Orta6,1 | — | %0,5 | 28 Mar 2023 |
24İzleyin | CVE-2023-3182İstismar yok | Membership Plugin - Restrict Content < 3.2.3 - Reflected XSSliquidweb · restrict content · CWE-79 | Orta6,1 | — | %0,5 | 17 Tem 2023 |
21İzleyin | CVE-2024-31432İstismar yok | WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerabilitystellarwp · restrict content · CWE-862 | Orta5,3 | — | %0,4 | 15 Nis 2024 |
21İzleyin | CVE-2024-13457İstismar yok | Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposureliquidweb · event tickets · CWE-284 | Orta5,3 | — | %0,3 | 30 Oca 2025 |
17İzleyin | CVE-2024-1319İstismar yok | Event Tickets Plus < 5.9.1 - Contributor+ Attendees Lists Disclosureliquidweb · event tickets · CWE-284 | Orta4,3 | — | %0,5 | 4 Mar 2024 |
17İzleyin | CVE-2024-1053İstismar yok | Event Tickets and Registration <= 5.8.1 - Missing Authorizationliquidweb · event tickets · CWE-284 | Orta4,3 | — | %0,4 | 22 Şub 2024 |
- CVE-2019-1612036İzleyin
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Expo
YüksekCVSS 8,8İstismar yokEPSS %3liquidweb · event tickets8 Eyl 2019
- CVE-2023-4766830İzleyin
WordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5Kavram kanıtıEPSS %1liquidweb · restrict content22 Kas 2023
- CVE-2025-1484430İzleyin
Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposure
YüksekCVSS 7,5İstismar yokEPSS %0liquidweb · restrict content16 Oca 2026
- CVE-2024-1109030İzleyin
Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
YüksekCVSS 7,5İstismar yokEPSS %0liquidweb · restrict content26 Oca 2025
- CVE-2024-131626İzleyin
Event Tickets and Registration < 5.8.1 - Contributor+ Arbitrary Events Access
OrtaCVSS 6,5İstismar yokEPSS %1liquidweb · event tickets4 Mar 2024
- CVE-2022-4582524İzleyin
WordPress WPComplete Plugin <= 2.9.4 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %1liquidweb · wpcomplete28 Mar 2023
- CVE-2023-318224İzleyin
Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS
OrtaCVSS 6,1İstismar yokEPSS %0liquidweb · restrict content17 Tem 2023
- CVE-2024-3143221İzleyin
WordPress Restrict Content plugin <= 3.2.8 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0stellarwp · restrict content15 Nis 2024
- CVE-2024-1345721İzleyin
Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %0liquidweb · event tickets30 Oca 2025
- CVE-2024-131917İzleyin
Event Tickets Plus < 5.9.1 - Contributor+ Attendees Lists Disclosure
OrtaCVSS 4,3İstismar yokEPSS %0liquidweb · event tickets4 Mar 2024
- CVE-2024-105317İzleyin
Event Tickets and Registration <= 5.8.1 - Missing Authorization
OrtaCVSS 4,3İstismar yokEPSS %0liquidweb · event tickets22 Şub 2024