plugin-planet kayıtları
plugin-planet üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %40,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-25138İstismar yok | User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Uploadplugin-planet · user submitted posts · CWE-434 | Kritik9,8 | — | %2,3 | 6 Haz 2023 |
39İzleyin | CVE-2023-45603İstismar yok | WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Uploadplugin-planet · user submitted posts · CWE-434 | Kritik9,8 | — | %0,9 | 20 Ara 2023 |
37İzleyin | CVE-2022-1165İstismar yok | Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofingplugin-planet · blackhole for bad bots · CWE-639 | Kritik9,1 | — | %1,7 | 4 Nis 2022 |
31İzleyin | CVE-2022-27849Kavram kanıtı | WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerabilityplugin-planet · simple ajax chat · CWE-200 | Yüksek7,5 | — | %4,6 | 15 Nis 2022 |
28İzleyin | CVE-2024-1983İstismar yok | Simple Ajax Chat < 20240223 - Unauthenticated Stored XSSplugin-planet · simple ajax chat · CWE-79 | Yüksek7,1 | — | %0,5 | 20 Mar 2024 |
25İzleyin | CVE-2021-24409Kavram kanıtı | Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)plugin-planet · prismatic · CWE-79 | Orta6,1 | — | %1,7 | 12 Tem 2021 |
24İzleyin | CVE-2016-11001İstismar yok | The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.plugin-planet · user submitted posts · CWE-79 | Orta6,1 | — | %1,2 | 20 Eyl 2019 |
24İzleyin | CVE-2022-25601İstismar yok | WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerabilityplugin-planet · contact form x · CWE-79 | Orta6,1 | — | %1,0 | 11 Mar 2022 |
24İzleyin | CVE-2022-25610İstismar yok | WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilityplugin-planet · simple ajax chat · CWE-79 | Orta6,1 | — | %0,7 | 25 Mar 2022 |
24İzleyin | CVE-2024-0979İstismar yok | Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scriptingplugin-planet · dashboard widgets suite · CWE-79 | Orta6,1 | — | %0,4 | 13 Haz 2024 |
21İzleyin | CVE-2021-24408İstismar yok | Prismatic < 2.8 - Contributor+ Stored XSSplugin-planet · prismatic · CWE-79 | Orta5,4 | — | %0,6 | 12 Tem 2021 |
21İzleyin | CVE-2023-5614İstismar yok | Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeplugin-planet · theme switcha · CWE-79 | Orta5,4 | — | %0,4 | 20 Eki 2023 |
21İzleyin | CVE-2023-4308İstismar yok | User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'plugin-planet · user submitted posts · CWE-79 | Orta5,4 | — | %0,4 | 15 Ağu 2023 |
21İzleyin | CVE-2023-4779İstismar yok | User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeplugin-planet · user submitted posts · CWE-79 | Orta5,4 | — | %0,4 | 6 Eyl 2023 |
21İzleyin | CVE-2023-4838İstismar yok | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,plugin-planet · simple download counter · CWE-79 | Orta5,4 | — | %0,4 | 8 Eyl 2023 |
21İzleyin | CVE-2024-2470İstismar yok | Simple Ajax Chat < 20240412 - Admin+ Stored XSSplugin-planet · simple ajax chat · CWE-79 | Orta5,4 | — | %0,3 | 4 Haz 2024 |
21İzleyin | CVE-2025-46240İstismar yok | WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerabilityplugin-planet · simple download counter · CWE-79 | Orta5,4 | — | %0,2 | 22 Nis 2025 |
21İzleyin | CVE-2025-46239İstismar yok | WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerabilityplugin-planet · theme switcha · CWE-79 | Orta5,4 | — | %0,2 | 22 Nis 2025 |
19İzleyin | CVE-2024-5002İstismar yok | User Submitted Posts < 20240516 - Admin+ Stored XSSplugin-planet · user submitted posts · CWE-79 | Orta4,8 | — | %0,4 | 13 Tem 2024 |
19İzleyin | CVE-2023-49743İstismar yok | WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)plugin-planet · dashboard widget suite · CWE-79 | Orta4,8 | — | %0,4 | 14 Ara 2023 |
19İzleyin | CVE-2023-26517İstismar yok | WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)plugin-planet · dashboard widget suite · CWE-79 | Orta4,8 | — | %0,4 | 6 May 2023 |
17İzleyin | CVE-2022-27850İstismar yok | WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilityplugin-planet · simple ajax chat · CWE-352 | Orta4,3 | — | %0,4 | 15 Nis 2022 |
- CVE-2019-2513840Planlayın
User Submitted Posts <= 20190312 - Unauthenticated Arbitrary File Upload
KritikCVSS 9,8İstismar yokEPSS %2plugin-planet · user submitted posts6 Haz 2023
- CVE-2023-4560339İzleyin
WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Upload
KritikCVSS 9,8İstismar yokEPSS %1plugin-planet · user submitted posts20 Ara 2023
- CVE-2022-116537İzleyin
Blackhole for Bad Bots < 3.3.2 - Arbitrary IP Address Blocking via IP Spoofing
KritikCVSS 9,1İstismar yokEPSS %2plugin-planet · blackhole for bad bots4 Nis 2022
- CVE-2022-2784931İzleyin
WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability
YüksekCVSS 7,5Kavram kanıtıEPSS %5plugin-planet · simple ajax chat15 Nis 2022
- CVE-2024-198328İzleyin
Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS
YüksekCVSS 7,1İstismar yokEPSS %0plugin-planet · simple ajax chat20 Mar 2024
- CVE-2021-2440925İzleyin
Prismatic < 2.8 - Reflected Cross-Site Scripting (XSS)
OrtaCVSS 6,1Kavram kanıtıEPSS %2plugin-planet · prismatic12 Tem 2021
- CVE-2016-1100124İzleyin
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
OrtaCVSS 6,1İstismar yokEPSS %1plugin-planet · user submitted posts20 Eyl 2019
- CVE-2022-2560124İzleyin
WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %1plugin-planet · contact form x11 Mar 2022
- CVE-2022-2561024İzleyin
WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %1plugin-planet · simple ajax chat25 Mar 2022
- CVE-2024-097924İzleyin
Dashboard Widgets Suite <= 3.4.3 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0plugin-planet · dashboard widgets suite13 Haz 2024
- CVE-2021-2440821İzleyin
Prismatic < 2.8 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1plugin-planet · prismatic12 Tem 2021
- CVE-2023-561421İzleyin
Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · theme switcha20 Eki 2023
- CVE-2023-430821İzleyin
User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · user submitted posts15 Ağu 2023
- CVE-2023-477921İzleyin
User Submitted Posts – Enable Users to Submit Posts from the Front End <= 20230811 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · user submitted posts6 Eyl 2023
- CVE-2023-483821İzleyin
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to,
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · simple download counter8 Eyl 2023
- CVE-2024-247021İzleyin
Simple Ajax Chat < 20240412 - Admin+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · simple ajax chat4 Haz 2024
- CVE-2025-4624021İzleyin
WordPress Simple Download Counter plugin <= 2.2 - Cross Site Scripting (XSS) Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · simple download counter22 Nis 2025
- CVE-2025-4623921İzleyin
WordPress Theme Switcha plugin <= 3.4 - Cross Site Scripting (XSS) Vulnerability
OrtaCVSS 5,4İstismar yokEPSS %0plugin-planet · theme switcha22 Nis 2025
- CVE-2024-500219İzleyin
User Submitted Posts < 20240516 - Admin+ Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %0plugin-planet · user submitted posts13 Tem 2024
- CVE-2023-4974319İzleyin
WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 4,8İstismar yokEPSS %0plugin-planet · dashboard widget suite14 Ara 2023
- CVE-2023-2651719İzleyin
WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 4,8İstismar yokEPSS %0plugin-planet · dashboard widget suite6 May 2023
- CVE-2022-2785017İzleyin
WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability
OrtaCVSS 4,3İstismar yokEPSS %0plugin-planet · simple ajax chat15 Nis 2022