tinymce kayıtları
tinymce üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %14,3
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %42,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2011-4825Silahlaştırılmış | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phptinymce · tinymce · CWE-94 | Yüksek7,5 | — | %39,2 | 14 Ara 2011 |
27İzleyin | CVE-2014-3845İstismar yok | Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijactinymce · color picker · CWE-352 | Orta6,8 | — | %1,0 | 22 May 2014 |
21İzleyin | CVE-2012-6112İstismar yok | classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2tinymce · spellchecker php · CWE-264 | Orta5,0 | — | %2,3 | 27 Oca 2013 |
21İzleyin | CVE-2014-3844İstismar yok | The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugintinymce · color picker · CWE-264 | Orta5,0 | — | %1,8 | 22 May 2014 |
20İzleyin | CVE-2012-3414Kavram kanıtı | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Imagetinymce · image manager · CWE-79 | Orta4,3 | — | %9,1 | 19 Tem 2013 |
18İzleyin | CVE-2013-2204İstismar yok | moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not considertinymce · media · CWE-20 | Orta4,3 | — | %2,9 | 8 Tem 2013 |
17İzleyin | CVE-2012-4230İstismar yok | The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elementinymce · tinymce · CWE-264 | Orta4,3 | — | %1,2 | 25 Nis 2014 |
- CVE-2011-482542Planlayın
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, php
YüksekCVSS 7,5SilahlaştırılmışEPSS %39tinymce · tinymce14 Ara 2011
- CVE-2014-384527İzleyin
Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijac
OrtaCVSS 6,8İstismar yokEPSS %1tinymce · color picker22 May 2014
- CVE-2012-611221İzleyin
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2
OrtaCVSS 5,0İstismar yokEPSS %2tinymce · spellchecker php27 Oca 2013
- CVE-2014-384421İzleyin
The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin
OrtaCVSS 5,0İstismar yokEPSS %2tinymce · color picker22 May 2014
- CVE-2012-341420İzleyin
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image
OrtaCVSS 4,3Kavram kanıtıEPSS %9tinymce · image manager19 Tem 2013
- CVE-2013-220418İzleyin
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider
OrtaCVSS 4,3İstismar yokEPSS %3tinymce · media8 Tem 2013
- CVE-2012-423017İzleyin
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elemen
OrtaCVSS 4,3İstismar yokEPSS %1tinymce · tinymce25 Nis 2014