TablePress kayıtları
tablepress üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %14,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-611 Improper Restriction of XML External Entity Reference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
28İzleyin | CVE-2019-20180İstismar yok | The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users.tablepress · tablepress · CWE-1236 | Orta6,8 | — | %2,3 | 9 Oca 2020 |
25İzleyin | CVE-2024-4354İstismar yok | TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebindtablepress · tablepress · CWE-918 | Orta6,4 | — | %0,4 | 7 Haz 2024 |
21İzleyin | CVE-2025-5096İstismar yok | TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameterstablepress · tablepress · CWE-79 | Orta5,4 | — | %0,4 | 23 May 2025 |
21İzleyin | CVE-2024-9595İstismar yok | TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scriptingtablepress · tablepress · CWE-79 | Orta5,4 | — | %0,3 | 12 Eki 2024 |
21İzleyin | CVE-2025-2685İstismar yok | TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scriptingtablepress · tablepress · CWE-79 | Orta5,4 | — | %0,3 | 27 Mar 2025 |
19İzleyin | CVE-2024-23825İstismar yok | TablePress SSRF vulnerability due to insufficient filtering of cloud provider hoststablepress · tablepress · CWE-918 | Orta4,9 | — | %0,5 | 30 Oca 2024 |
17İzleyin | CVE-2017-10889İstismar yok | TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.tablepress · tablepress · CWE-611 | Orta4,3 | — | %1,1 | 17 Kas 2017 |
- CVE-2019-2018028İzleyin
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users.
OrtaCVSS 6,8İstismar yokEPSS %2tablepress · tablepress9 Oca 2020
- CVE-2024-435425İzleyin
TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind
OrtaCVSS 6,4İstismar yokEPSS %0tablepress · tablepress7 Haz 2024
- CVE-2025-509621İzleyin
TablePress <= 3.1.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters
OrtaCVSS 5,4İstismar yokEPSS %0tablepress · tablepress23 May 2025
- CVE-2024-959521İzleyin
TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0tablepress · tablepress12 Eki 2024
- CVE-2025-268521İzleyin
TablePress – Tables in WordPress made easy <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0tablepress · tablepress27 Mar 2025
- CVE-2024-2382519İzleyin
TablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts
OrtaCVSS 4,9İstismar yokEPSS %1tablepress · tablepress30 Oca 2024
- CVE-2017-1088917İzleyin
TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.
OrtaCVSS 4,3İstismar yokEPSS %1tablepress · tablepress17 Kas 2017