Themify kayıtları
themify üreticisine ait 32 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-862 Missing Authorization2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-269 Improper Privilege Management1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
32 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2013-20002İstismar yok | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/ththemify · framework · CWE-434 | Kritik9,8 | — | %3,9 | 17 Haz 2021 |
35İzleyin | CVE-2023-46149İstismar yok | WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Uploadthemify · ultra · CWE-434 | Yüksek8,8 | — | %0,6 | 20 Ara 2023 |
35İzleyin | CVE-2023-46145İstismar yok | WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerabilitythemify · ultra · CWE-269 | Yüksek8,8 | — | %0,6 | 17 May 2024 |
35İzleyin | CVE-2023-46147İstismar yok | WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to PHP Object Injectionthemify · ultra · CWE-502 | Yüksek8,8 | — | %0,5 | 20 Ara 2023 |
35İzleyin | CVE-2023-46148İstismar yok | WordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerabilitythemify · ultra · CWE-862 | Yüksek8,8 | — | %0,4 | 19 Haz 2024 |
35İzleyin | CVE-2023-46146İstismar yok | WordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerabilitythemify · ultra · CWE-862 | Yüksek8,8 | — | %0,4 | 19 Haz 2024 |
35İzleyin | CVE-2024-24872İstismar yok | WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF)themify · builder · CWE-352 | Yüksek8,8 | — | %0,2 | 21 Şub 2024 |
30İzleyin | CVE-2024-6027İstismar yok | Themify - WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameterthemify · product filter · CWE-89 | Yüksek7,5 | — | %0,8 | 21 Haz 2024 |
26İzleyin | CVE-2024-56216İstismar yok | WordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerabilitythemify · builder · CWE-98 | Orta6,5 | — | %0,5 | 31 Ara 2024 |
24İzleyin | CVE-2022-1532İstismar yok | Themify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scriptingthemify · woocommerce product filter · CWE-79 | Orta6,1 | — | %0,8 | 13 Haz 2022 |
24İzleyin | CVE-2024-3032Kavram kanıtı | Themify Builder < 7.5.8 - Open Redirectthemify · builder · CWE-601 | Orta6,1 | — | %0,8 | 13 Haz 2024 |
24İzleyin | CVE-2022-1047İstismar yok | Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scriptingthemify · post type builder search addon · CWE-79 | Orta6,1 | — | %0,8 | 9 May 2022 |
24İzleyin | CVE-2023-2654İstismar yok | Conditional Menus < 1.2.1 - Reflected XSSthemify · conditional menus · CWE-79 | Orta6,1 | — | %0,5 | 19 Haz 2023 |
24İzleyin | CVE-2024-2278İstismar yok | WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSSthemify · woocommerce product filter · CWE-79 | Orta6,1 | — | %0,4 | 1 Nis 2024 |
24İzleyin | CVE-2024-9385İstismar yok | Themify Builder <= 7.6.2 - Reflected Cross-Site Scriptingthemify · builder · CWE-79 | Orta6,1 | — | %0,4 | 4 Eki 2024 |
24İzleyin | CVE-2024-13319İstismar yok | Themify Builder <= 7.6.5 - Reflected Cross-Site Scriptingthemify · themify builder · CWE-79 | Orta6,1 | — | %0,3 | 22 Oca 2025 |
21İzleyin | CVE-2021-24129İstismar yok | Themify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site Scriptingthemify · portfolio post · CWE-79 | Orta5,4 | — | %0,7 | 18 Mar 2021 |
21İzleyin | CVE-2022-0200İstismar yok | Themify Portfolio Post < 1.1.7 - Reflected Cross-Site Scriptingthemify · portfolio post · CWE-79 | Orta5,4 | — | %0,6 | 14 Şub 2022 |
21İzleyin | CVE-2022-4464İstismar yok | Themify Portfolio Post < 1.2.1 - Contributor+ Stored XSSthemify · portfolio post · CWE-79 | Orta5,4 | — | %0,5 | 16 Oca 2023 |
21İzleyin | CVE-2023-0362İstismar yok | Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSSthemify · portfolio post · CWE-79 | Orta5,4 | — | %0,5 | 13 Şub 2023 |
21İzleyin | CVE-2022-4787İstismar yok | Themify Shortcodes < 2.0.8 - Contributor+ Stored XSS via Shortcodethemify · shortcodes · CWE-79 | Orta5,4 | — | %0,5 | 30 Oca 2023 |
21İzleyin | CVE-2024-4567İstismar yok | Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcodethemify · themify shortcodes · CWE-79 | Orta5,4 | — | %0,4 | 14 May 2024 |
21İzleyin | CVE-2022-32970İstismar yok | WordPress Themify Portfolio Post Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)themify · portfolio post · CWE-79 | Orta5,4 | — | %0,4 | 10 May 2023 |
21İzleyin | CVE-2024-2732İstismar yok | Themify Shortcodes <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scriptingthemify · themify shortcodes · CWE-79 | Orta5,4 | — | %0,3 | 25 Mar 2024 |
21İzleyin | CVE-2023-51693İstismar yok | WordPress Themify Icons Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)themify · icons · CWE-79 | Orta5,4 | — | %0,3 | 1 Şub 2024 |
- CVE-2013-2000240Planlayın
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/th
KritikCVSS 9,8İstismar yokEPSS %4themify · framework17 Haz 2021
- CVE-2023-4614935İzleyin
WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1themify · ultra20 Ara 2023
- CVE-2023-4614535İzleyin
WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1themify · ultra17 May 2024
- CVE-2023-4614735İzleyin
WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to PHP Object Injection
YüksekCVSS 8,8İstismar yokEPSS %0themify · ultra20 Ara 2023
- CVE-2023-4614835İzleyin
WordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0themify · ultra19 Haz 2024
- CVE-2023-4614635İzleyin
WordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0themify · ultra19 Haz 2024
- CVE-2024-2487235İzleyin
WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0themify · builder21 Şub 2024
- CVE-2024-602730İzleyin
Themify - WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter
YüksekCVSS 7,5İstismar yokEPSS %1themify · product filter21 Haz 2024
- CVE-2024-5621626İzleyin
WordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0themify · builder31 Ara 2024
- CVE-2022-153224İzleyin
Themify - WooCommerce Product Filter < 1.3.8 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1themify · woocommerce product filter13 Haz 2022
- CVE-2024-303224İzleyin
Themify Builder < 7.5.8 - Open Redirect
OrtaCVSS 6,1Kavram kanıtıEPSS %1themify · builder13 Haz 2024
- CVE-2022-104724İzleyin
Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1themify · post type builder search addon9 May 2022
- CVE-2023-265424İzleyin
Conditional Menus < 1.2.1 - Reflected XSS
OrtaCVSS 6,1İstismar yokEPSS %0themify · conditional menus19 Haz 2023
- CVE-2024-227824İzleyin
WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %0themify · woocommerce product filter1 Nis 2024
- CVE-2024-938524İzleyin
Themify Builder <= 7.6.2 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0themify · builder4 Eki 2024
- CVE-2024-1331924İzleyin
Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0themify · themify builder22 Oca 2025
- CVE-2021-2412921İzleyin
Themify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %1themify · portfolio post18 Mar 2021
- CVE-2022-020021İzleyin
Themify Portfolio Post < 1.1.7 - Reflected Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %1themify · portfolio post14 Şub 2022
- CVE-2022-446421İzleyin
Themify Portfolio Post < 1.2.1 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1themify · portfolio post16 Oca 2023
- CVE-2023-036221İzleyin
Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1themify · portfolio post13 Şub 2023
- CVE-2022-478721İzleyin
Themify Shortcodes < 2.0.8 - Contributor+ Stored XSS via Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0themify · shortcodes30 Oca 2023
- CVE-2024-456721İzleyin
Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0themify · themify shortcodes14 May 2024
- CVE-2022-3297021İzleyin
WordPress Themify Portfolio Post Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0themify · portfolio post10 May 2023
- CVE-2024-273221İzleyin
Themify Shortcodes <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %0themify · themify shortcodes25 Mar 2024
- CVE-2023-5169321İzleyin
WordPress Themify Icons Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0themify · icons1 Şub 2024