İçeriğe atla
Noroxi

themeisle kayıtları

themeisle üreticisine ait 61 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%27,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

61 kayıt
  • CVE-2019-16932
    52Planlayın

    A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

    KritikCVSS 10,0Kavram kanıtıEPSS %39

    themeisle · visualizer30 Eyl 2019

  • CVE-2023-2288
    40Planlayın

    Otter - Gutenberg Blocks < 2.2.6 - Author+ PHAR Deserialization

    YüksekCVSS 8,8İstismar yokEPSS %18

    themeisle · otter30 May 2023

  • CVE-2024-3962
    39İzleyin

    Product Addons & Fields for WooCommerce <= 32.0.18 - Unauthenticated Arbitrary File Upload via ppom_upload_file

    KritikCVSS 9,8İstismar yokEPSS %1

    themeisle · product addons \& fields for woocommerce26 Nis 2024

  • CVE-2023-33927
    39İzleyin

    WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injection

    KritikCVSS 9,8İstismar yokEPSS %1

    themeisle · multiple page generator31 Eki 2023

  • CVE-2022-2444
    36İzleyin

    Visualizer: Tables and Charts Manager for WordPress <= 3.7.9 - Authenticated (Contributor+) PHAR Deserialization

    YüksekCVSS 8,8İstismar yokEPSS %2

    themeisle · visualizer18 Tem 2022

  • CVE-2024-1317
    35İzleyin

    RSS Aggregator by Feedzy <= 4.4.2 - Authenticated(Contributor+) SQL Injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    themeisle · rss aggregator by feedzy28 Şub 2024

  • CVE-2024-47325
    35İzleyin

    WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.7 - SQL Injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    themeisle · multiple page generator20 Eki 2024

  • CVE-2024-35736
    35İzleyin

    WordPress Visualizer plugin <= 3.11.1 - SQL Injection vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    themeisle · visualizer8 Haz 2024

  • CVE-2024-30235
    35İzleyin

    WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Broken Access Control vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    themeisle · multiple page generator26 Mar 2024

  • CVE-2022-47143
    35İzleyin

    WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    themeisle · multiple page generator14 Mar 2023

  • CVE-2024-31301
    35İzleyin

    WordPress Multiple Page Generator Plugin – MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    themeisle · multiple page generator12 Nis 2024

  • CVE-2024-10705
    32İzleyin

    Multiple Page Generator Plugin – MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl

    YüksekCVSS 8,1İstismar yokEPSS %0

    themeisle · multiple page generator26 Oca 2025

  • CVE-2023-47529
    30İzleyin

    WordPress Cloud Templates & Patterns collection Plugin <= 1.2.2 is vulnerable to Sensitive Data Exposure

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    themeisle · cloud templates \& patterns collection23 Kas 2023

  • CVE-2024-11219
    30İzleyin

    Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View

    YüksekCVSS 7,5İstismar yokEPSS %1

    themeisle · otter blocks27 Kas 2024

  • CVE-2023-2607
    28İzleyin

    Multiple Page Generator Plugin <= 3.3.17 - Authenticated (Administrator+) SQL Injection

    YüksekCVSS 7,2İstismar yokEPSS %1

    themeisle · multiple page generator9 Haz 2023

  • CVE-2024-27951
    28İzleyin

    WordPress Multiple Page Generator Plugin <= 3.4.0 - Auth. Remote Code Execution (RCE) vulnerability

    YüksekCVSS 7,2İstismar yokEPSS %1

    themeisle · multiple page generator3 Nis 2024

  • CVE-2021-24158
    26İzleyin

    Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege Escalation

    OrtaCVSS 6,5İstismar yokEPSS %1

    themeisle · orbit fox5 Nis 2021

  • CVE-2022-1576
    26İzleyin

    WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF

    OrtaCVSS 6,5İstismar yokEPSS %1

    themeisle · wp maintenance mode \& coming soon11 Tem 2022

  • CVE-2024-1318
    26İzleyin

    RSS Aggregator by Feedzy <= 4.4.2 - Missing Authorization to Arbitrary Page Creation and Publication

    OrtaCVSS 6,5İstismar yokEPSS %1

    themeisle · rss aggregator by feedzy28 Şub 2024

  • CVE-2019-16931
    25İzleyin

    A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript w

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    themeisle · visualizer3 Eki 2019

  • CVE-2023-6805
    25İzleyin

    RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Fo

    OrtaCVSS 6,4İstismar yokEPSS %0

    themeisle · rss aggregator by feedzy17 Nis 2024

  • CVE-2023-2256
    24İzleyin

    Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    themeisle · product addons \& fields for woocommerce30 May 2023

  • CVE-2024-1691
    24İzleyin

    Otter Blocks PRO <= 2.6.3 - Unauthenticated Stored Cross-Site Scripting via SVG Upload

    OrtaCVSS 6,1İstismar yokEPSS %0

    themeisle · otter blocks13 Mar 2024

  • CVE-2024-27958
    24İzleyin

    WordPress Visualizer plugin <= 3.10.5 - Reflected Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %0

    themeisle · visualizer17 Mar 2024

  • CVE-2024-2729
    24İzleyin

    Otter Blocks < 2.6.6 - Contributor+ Stored XSS

    OrtaCVSS 6,1İstismar yokEPSS %0

    themeisle · otter blocks18 Nis 2024