stellarwp kayıtları
stellarwp üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-287 Improper Authentication1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2024-8275Kavram kanıtı | The Events Calendar <= 6.6.4 - Unauthenticated SQL Injectionstellarwp · the events calendar · CWE-89 | Kritik9,8 | — | %49,9 | 25 Eyl 2024 |
37İzleyin | CVE-2024-4180Kavram kanıtı | The Events Calendar < 6.4.0.1 - Reflected XSSstellarwp · the events calendar · CWE-79 | Kritik9,1 | — | %1,8 | 4 Haz 2024 |
30İzleyin | CVE-2023-6203İstismar yok | The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Readstellarwp · the events calendar · CWE-287 | Yüksek7,5 | — | %0,8 | 18 Ara 2023 |
29İzleyin | CVE-2024-6931İstismar yok | The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scriptingstellarwp · the events calendar · CWE-79 | Orta6,1 | — | %16,7 | 27 Eyl 2024 |
24İzleyin | CVE-2019-15109İstismar yok | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.stellarwp · the events calendar · CWE-79 | Orta6,1 | — | %1,1 | 21 Ağu 2019 |
21İzleyin | CVE-2024-5333Kavram kanıtı | The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosurestellarwp · the events calendar · CWE-639 | Orta5,3 | — | %1,1 | 16 Ara 2024 |
21İzleyin | CVE-2023-6557İstismar yok | The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposurestellarwp · the events calendar · CWE-862 | Orta5,3 | — | %0,6 | 5 Şub 2024 |
21İzleyin | CVE-2025-5144İstismar yok | The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scriptingstellarwp · the events calendar · CWE-79 | Orta5,4 | — | %0,3 | 11 Haz 2025 |
19İzleyin | CVE-2024-8493İstismar yok | The Events Calendar < 6.6.4 - Admin+ Stored XSSstellarwp · the events calendar · CWE-79 | Orta4,8 | — | %0,3 | 15 May 2025 |
19İzleyin | CVE-2024-10939İstismar yok | Image Widget < 4.4.11 - Admin+ Stored XSSstellarwp · image widget · CWE-79 | Orta4,8 | — | %0,3 | 13 Ara 2024 |
- CVE-2024-827554Planlayın
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %50stellarwp · the events calendar25 Eyl 2024
- CVE-2024-418037İzleyin
The Events Calendar < 6.4.0.1 - Reflected XSS
KritikCVSS 9,1Kavram kanıtıEPSS %2stellarwp · the events calendar4 Haz 2024
- CVE-2023-620330İzleyin
The Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read
YüksekCVSS 7,5İstismar yokEPSS %1stellarwp · the events calendar18 Ara 2023
- CVE-2024-693129İzleyin
The Events Calendar <= 6.6.3 - Unauthenticated Stored Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %17stellarwp · the events calendar27 Eyl 2024
- CVE-2019-1510924İzleyin
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
OrtaCVSS 6,1İstismar yokEPSS %1stellarwp · the events calendar21 Ağu 2019
- CVE-2024-533321İzleyin
The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
OrtaCVSS 5,3Kavram kanıtıEPSS %1stellarwp · the events calendar16 Ara 2024
- CVE-2023-655721İzleyin
The Events Calendar <= 6.2.8.2 - Unauthenticated Sensitive Information Exposure
OrtaCVSS 5,3İstismar yokEPSS %1stellarwp · the events calendar5 Şub 2024
- CVE-2025-514421İzleyin
The Events Calendar <= 6.13.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0stellarwp · the events calendar11 Haz 2025
- CVE-2024-849319İzleyin
The Events Calendar < 6.6.4 - Admin+ Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %0stellarwp · the events calendar15 May 2025
- CVE-2024-1093919İzleyin
Image Widget < 4.4.11 - Admin+ Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %0stellarwp · image widget13 Ara 2024