ThimPress kayıtları
thimpress üreticisine ait 71 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %4,2
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %33,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')16
- CWE-862 Missing Authorization6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-502 Deserialization of Untrusted Data2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
71 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2023-5652Kavram kanıtı | WP Hotel Booking < 2.0.8 - Unauthenticated SQLithimpress · wp hotel booking · CWE-89 | Kritik9,8 | — | %63,7 | 20 Kas 2023 |
50Planlayın | CVE-2020-6010Silahlaştırılmış | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Yüksek8,8 | — | %49,2 | 30 Nis 2020 |
50Planlayın | CVE-2024-4434Kavram kanıtı | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injectionthimpress · learnpress · CWE-89 | Kritik9,8 | — | %36,9 | 14 May 2024 |
49Planlayın | CVE-2024-8522Silahlaştırılmış | LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'thimpress · learnpress · CWE-89 | Yüksek7,5 | — | %62,9 | 12 Eyl 2024 |
45Planlayın | CVE-2023-6567Kavram kanıtı | LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_bythimpress · learnpress · CWE-89 | Yüksek7,5 | — | %51,4 | 11 Oca 2024 |
44Planlayın | CVE-2020-29047Kavram kanıtı | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operatithimpress · wp hotel booking · CWE-502 | Kritik9,8 | — | %16,0 | 3 Mar 2021 |
42Planlayın | CVE-2023-6634Kavram kanıtı | LearnPress <= 4.2.5.7 - Command Injectionthimpress · learnpress · CWE-88 | Kritik9,8 | — | %8,5 | 11 Oca 2024 |
41Planlayın | CVE-2022-47615Kavram kanıtı | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusionthimpress · learnpress · CWE-434 | Kritik9,8 | — | %5,1 | 26 Oca 2023 |
40Planlayın | CVE-2024-7855İstismar yok | WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Uploadthimpress · wp hotel booking · CWE-434 | Yüksek8,8 | — | %17,7 | 2 Eki 2024 |
40Planlayın | CVE-2022-45808Kavram kanıtı | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Kritik9,8 | — | %4,3 | 26 Oca 2023 |
40Planlayın | CVE-2024-3605Kavram kanıtı | WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injectionthimpress · wp hotel booking · CWE-89 | Kritik9,8 | — | %4,2 | 19 Haz 2024 |
39İzleyin | CVE-2021-24951İstismar yok | LearnPress < 4.1.4 - Admin+ SQL Injectionthimpress · learnpress · CWE-89 | Kritik9,8 | — | %1,6 | 13 Ara 2021 |
39İzleyin | CVE-2024-30508İstismar yok | WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerabilitythimpress · wp hotel booking · CWE-862 | Kritik9,8 | — | %0,5 | 29 Mar 2024 |
39İzleyin | CVE-2025-28979İstismar yok | WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerabilitythimpress · wp pipes · CWE-98 | Kritik9,8 | — | %0,5 | 14 Ağu 2025 |
39İzleyin | CVE-2023-36515İstismar yok | WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerabilitythimpress · learnpress · CWE-862 | Kritik9,8 | — | %0,4 | 19 Haz 2024 |
39İzleyin | CVE-2025-28982İstismar yok | WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerabilitythimpress · wp pipes · CWE-89 | Kritik9,8 | — | %0,4 | 16 Tem 2025 |
36İzleyin | CVE-2025-48267İstismar yok | WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerabilitythimpress · wp pipes · CWE-22 | Kritik9,1 | — | %0,5 | 9 Haz 2025 |
35İzleyin | CVE-2024-4397İstismar yok | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Uploadthimpress · learnpress · CWE-434 | Yüksek8,8 | — | %1,0 | 14 May 2024 |
35İzleyin | CVE-2022-45820İstismar yok | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Yüksek8,8 | — | %1,0 | 26 Oca 2023 |
35İzleyin | CVE-2024-6589İstismar yok | LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusionthimpress · learnpress · CWE-98 | Yüksek8,8 | — | %0,8 | 25 Tem 2024 |
35İzleyin | CVE-2024-51582İstismar yok | WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerabilitythimpress · wp hotel booking · CWE-35 | Yüksek8,8 | — | %0,5 | 4 Kas 2024 |
35İzleyin | CVE-2023-36516İstismar yok | WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerabilitythimpress · learnpress · CWE-862 | Yüksek8,8 | — | %0,5 | 19 Haz 2024 |
35İzleyin | CVE-2024-7717İstismar yok | WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injectionthimpress · wp events manager · CWE-89 | Yüksek8,8 | — | %0,5 | 31 Ağu 2024 |
35İzleyin | CVE-2024-2115İstismar yok | LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalationthimpress · learnpress · CWE-352 | Yüksek8,8 | — | %0,3 | 5 Nis 2024 |
35İzleyin | CVE-2024-39641İstismar yok | WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerabilitythimpress · learnpress · CWE-352 | Yüksek8,8 | — | %0,2 | 26 Ağu 2024 |
- CVE-2023-565258Planlayın
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
KritikCVSS 9,8Kavram kanıtıEPSS %64thimpress · wp hotel booking20 Kas 2023
- CVE-2020-601050Planlayın
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
YüksekCVSS 8,8SilahlaştırılmışEPSS %49thimpress · learnpress30 Nis 2020
- CVE-2024-443450Planlayın
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %37thimpress · learnpress14 May 2024
- CVE-2024-852249Planlayın
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
YüksekCVSS 7,5SilahlaştırılmışEPSS %63thimpress · learnpress12 Eyl 2024
- CVE-2023-656745Planlayın
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
YüksekCVSS 7,5Kavram kanıtıEPSS %51thimpress · learnpress11 Oca 2024
- CVE-2020-2904744Planlayın
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operati
KritikCVSS 9,8Kavram kanıtıEPSS %16thimpress · wp hotel booking3 Mar 2021
- CVE-2023-663442Planlayın
LearnPress <= 4.2.5.7 - Command Injection
KritikCVSS 9,8Kavram kanıtıEPSS %9thimpress · learnpress11 Oca 2024
- CVE-2022-4761541Planlayın
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %5thimpress · learnpress26 Oca 2023
- CVE-2024-785540Planlayın
WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %18thimpress · wp hotel booking2 Eki 2024
- CVE-2022-4580840Planlayın
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %4thimpress · learnpress26 Oca 2023
- CVE-2024-360540Planlayın
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %4thimpress · wp hotel booking19 Haz 2024
- CVE-2021-2495139İzleyin
LearnPress < 4.1.4 - Admin+ SQL Injection
KritikCVSS 9,8İstismar yokEPSS %2thimpress · learnpress13 Ara 2021
- CVE-2024-3050839İzleyin
WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %1thimpress · wp hotel booking29 Mar 2024
- CVE-2025-2897939İzleyin
WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0thimpress · wp pipes14 Ağu 2025
- CVE-2023-3651539İzleyin
WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %0thimpress · learnpress19 Haz 2024
- CVE-2025-2898239İzleyin
WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0thimpress · wp pipes16 Tem 2025
- CVE-2025-4826736İzleyin
WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerability
KritikCVSS 9,1İstismar yokEPSS %0thimpress · wp pipes9 Haz 2025
- CVE-2024-439735İzleyin
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1thimpress · learnpress14 May 2024
- CVE-2022-4582035İzleyin
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1thimpress · learnpress26 Oca 2023
- CVE-2024-658935İzleyin
LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion
YüksekCVSS 8,8İstismar yokEPSS %1thimpress · learnpress25 Tem 2024
- CVE-2024-5158235İzleyin
WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1thimpress · wp hotel booking4 Kas 2024
- CVE-2023-3651635İzleyin
WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1thimpress · learnpress19 Haz 2024
- CVE-2024-771735İzleyin
WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %0thimpress · wp events manager31 Ağu 2024
- CVE-2024-211535İzleyin
LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %0thimpress · learnpress5 Nis 2024
- CVE-2024-3964135İzleyin
WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0thimpress · learnpress26 Ağu 2024