UpdraftPlus kayıtları
updraftplus üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %10,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2017-16871İstismar yok | The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plupdraftplus · updraftplus · CWE-94 | Yüksek8,1 | — | %1,6 | 17 Kas 2017 |
32İzleyin | CVE-2017-16870İstismar yok | The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.updraftplus · updraftplus · CWE-918 | Yüksek8,1 | — | %1,0 | 17 Kas 2017 |
29İzleyin | CVE-2023-0157Kavram kanıtı | All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSSupdraftplus · all-in-one security · CWE-79 | Orta4,8 | — | %32,5 | 10 Nis 2023 |
27İzleyin | CVE-2022-0633İstismar yok | UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Downloadupdraftplus · updraftplus · CWE-863 | Orta6,5 | — | %2,1 | 17 Şub 2022 |
26İzleyin | CVE-2022-0864Kavram kanıtı | UpdraftPlus < 1.22.9 - Reflected Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Orta6,1 | — | %7,4 | 4 Nis 2022 |
25İzleyin | CVE-2023-0156Kavram kanıtı | All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversalupdraftplus · all-in-one security · CWE-22 | Orta4,9 | — | %19,9 | 10 Nis 2023 |
24İzleyin | CVE-2023-1119Kavram kanıtı | Multiple Plugins - Cross-Site Scripting From Third-party Librarysrbtranslatin project · srbtranslatin · CWE-79 | Orta6,1 | — | %1,2 | 10 Tem 2023 |
24İzleyin | CVE-2021-25022İstismar yok | UpdraftPlus < 1.16.66 - Reflected Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Orta6,1 | — | %1,1 | 3 Oca 2022 |
24İzleyin | CVE-2015-9360İstismar yok | The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().updraftplus · updraftplus · CWE-79 | Orta6,1 | — | %1,0 | 28 Ağu 2019 |
24İzleyin | CVE-2017-18593İstismar yok | The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.updraftplus · updraftplus · CWE-79 | Orta6,1 | — | %0,9 | 28 Ağu 2019 |
24İzleyin | CVE-2021-25089İstismar yok | UpdraftPlus < 1.16.69 - Reflected Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Orta6,1 | — | %0,8 | 1 Şub 2022 |
24İzleyin | CVE-2024-1037İstismar yok | All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scriptingupdraftplus · all-in-one security · CWE-79 | Orta6,1 | — | %0,6 | 7 Şub 2024 |
24İzleyin | CVE-2023-26530İstismar yok | WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)updraftplus · updraft · CWE-79 | Orta6,1 | — | %0,4 | 17 Ağu 2023 |
24İzleyin | CVE-2023-32960İstismar yok | WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)updraftplus · updraftplus · CWE-352 | Orta6,1 | — | %0,2 | 22 Haz 2023 |
21İzleyin | CVE-2022-4346İstismar yok | All In One WP Security & Firewall < 5.1.3 - Configuration Leakupdraftplus · all-in-one security · CWE-552 | Orta5,3 | — | %0,7 | 23 Oca 2023 |
21İzleyin | CVE-2022-4097İstismar yok | All In One WP Security & Firewall < 5.0.8 - IP Spoofingupdraftplus · all-in-one security · CWE-639 | Orta5,3 | — | %0,6 | 12 Ara 2022 |
21İzleyin | CVE-2023-5982İstismar yok | UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Updateupdraftplus · updraftplus · CWE-352 | Orta5,4 | — | %0,2 | 7 Kas 2023 |
19İzleyin | CVE-2021-24423İstismar yok | UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scriptingupdraftplus · updraftplus · CWE-79 | Orta4,8 | — | %0,6 | 24 Oca 2022 |
16İzleyin | CVE-2025-3951İstismar yok | WP-Optimize < 4.2.0 - Admin+ SQLiupdraftplus · wp-optimize · CWE-89 | Orta4,1 | — | %0,3 | 2 Haz 2025 |
- CVE-2017-1687132İzleyin
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/pl
YüksekCVSS 8,1İstismar yokEPSS %2updraftplus · updraftplus17 Kas 2017
- CVE-2017-1687032İzleyin
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.
YüksekCVSS 8,1İstismar yokEPSS %1updraftplus · updraftplus17 Kas 2017
- CVE-2023-015729İzleyin
All-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS
OrtaCVSS 4,8Kavram kanıtıEPSS %32updraftplus · all-in-one security10 Nis 2023
- CVE-2022-063327İzleyin
UpdraftPlus Free < 1.22.3 & Premium < 2.22.3 - Subscriber+ Backup Download
OrtaCVSS 6,5İstismar yokEPSS %2updraftplus · updraftplus17 Şub 2022
- CVE-2022-086426İzleyin
UpdraftPlus < 1.22.9 - Reflected Cross-Site Scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %7updraftplus · updraftplus4 Nis 2022
- CVE-2023-015625İzleyin
All-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal
OrtaCVSS 4,9Kavram kanıtıEPSS %20updraftplus · all-in-one security10 Nis 2023
- CVE-2023-111924İzleyin
Multiple Plugins - Cross-Site Scripting From Third-party Library
OrtaCVSS 6,1Kavram kanıtıEPSS %1srbtranslatin project · srbtranslatin10 Tem 2023
- CVE-2021-2502224İzleyin
UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1updraftplus · updraftplus3 Oca 2022
- CVE-2015-936024İzleyin
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
OrtaCVSS 6,1İstismar yokEPSS %1updraftplus · updraftplus28 Ağu 2019
- CVE-2017-1859324İzleyin
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
OrtaCVSS 6,1İstismar yokEPSS %1updraftplus · updraftplus28 Ağu 2019
- CVE-2021-2508924İzleyin
UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1updraftplus · updraftplus1 Şub 2022
- CVE-2024-103724İzleyin
All-In-One Security (AIOS) – Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1updraftplus · all-in-one security7 Şub 2024
- CVE-2023-2653024İzleyin
WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0updraftplus · updraft17 Ağu 2023
- CVE-2023-3296024İzleyin
WordPress UpdraftPlus Plugin <= 1.23.3 is vulnerable to Cross Site Request Forgery (CSRF)
OrtaCVSS 6,1İstismar yokEPSS %0updraftplus · updraftplus22 Haz 2023
- CVE-2022-434621İzleyin
All In One WP Security & Firewall < 5.1.3 - Configuration Leak
OrtaCVSS 5,3İstismar yokEPSS %1updraftplus · all-in-one security23 Oca 2023
- CVE-2022-409721İzleyin
All In One WP Security & Firewall < 5.0.8 - IP Spoofing
OrtaCVSS 5,3İstismar yokEPSS %1updraftplus · all-in-one security12 Ara 2022
- CVE-2023-598221İzleyin
UpdraftPlus <= 1.23.10 - Cross-Site Request Forgery to Google Drive Storage Update
OrtaCVSS 5,4İstismar yokEPSS %0updraftplus · updraftplus7 Kas 2023
- CVE-2021-2442319İzleyin
UpdraftPlus < 1.16.59 - Admin+ Stored Cross-Site Scripting
OrtaCVSS 4,8İstismar yokEPSS %1updraftplus · updraftplus24 Oca 2022
- CVE-2025-395116İzleyin
WP-Optimize < 4.2.0 - Admin+ SQLi
OrtaCVSS 4,1İstismar yokEPSS %0updraftplus · wp-optimize2 Haz 2025