optiontree project kayıtları
optiontree project üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-15319İstismar yok | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.optiontree project · optiontree · CWE-502 | Kritik9,8 | — | %2,1 | 22 Ağu 2019 |
40Planlayın | CVE-2019-15320İstismar yok | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.optiontree project · optiontree · CWE-502 | Kritik9,8 | — | %2,1 | 22 Ağu 2019 |
40Planlayın | CVE-2019-15321İstismar yok | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.optiontree project · optiontree · CWE-502 | Kritik9,8 | — | %2,1 | 22 Ağu 2019 |
24İzleyin | CVE-2015-9320İstismar yok | The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.optiontree project · optiontree · CWE-79 | Orta6,1 | — | %0,9 | 20 Ağu 2019 |
24İzleyin | CVE-2016-10895İstismar yok | The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.optiontree project · optiontree · CWE-79 | Orta6,1 | — | %0,9 | 20 Ağu 2019 |
- CVE-2019-1531940Planlayın
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
KritikCVSS 9,8İstismar yokEPSS %2optiontree project · optiontree22 Ağu 2019
- CVE-2019-1532040Planlayın
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
KritikCVSS 9,8İstismar yokEPSS %2optiontree project · optiontree22 Ağu 2019
- CVE-2019-1532140Planlayın
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
KritikCVSS 9,8İstismar yokEPSS %2optiontree project · optiontree22 Ağu 2019
- CVE-2015-932024İzleyin
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
OrtaCVSS 6,1İstismar yokEPSS %1optiontree project · optiontree20 Ağu 2019
- CVE-2016-1089524İzleyin
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
OrtaCVSS 6,1İstismar yokEPSS %1optiontree project · optiontree20 Ağu 2019