webfactoryltd kayıtları
webfactoryltd üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %11,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-862 Missing Authorization5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-330 Use of Insufficiently Random Values1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2020-7048Kavram kanıtı | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the databaswebfactoryltd · wp database reset · CWE-306 | Kritik9,1 | — | %22,9 | 16 Oca 2020 |
36İzleyin | CVE-2020-7047İstismar yok | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the abilitywebfactoryltd · wp database reset · CWE-269 | Yüksek8,8 | — | %2,5 | 16 Oca 2020 |
36İzleyin | CVE-2019-19915İstismar yok | The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delwebfactoryltd · 301 redirects · CWE-352 | Kritik9,0 | — | %0,9 | 19 Ara 2019 |
35İzleyin | CVE-2020-6167İstismar yok | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, injectwebfactoryltd · minimal coming soon \& maintenance mode · CWE-352 | Yüksek8,8 | — | %0,9 | 9 Oca 2020 |
35İzleyin | CVE-2021-36908İstismar yok | WordPress WP Reset PRO Premium Plugin <= 5.98 - Cross-Site Request Forgery (CSRF) vulnerabilitywebfactoryltd · wp reset pro · CWE-352 | Yüksek8,8 | — | %0,7 | 18 Kas 2021 |
33İzleyin | CVE-2021-36909İstismar yok | WordPress WP Reset PRO Premium plugin <= 5.98 - Authenticated Database Reset vulnerabilitywebfactoryltd · wp reset pro · CWE-284 | Yüksek8,1 | — | %1,9 | 18 Kas 2021 |
31İzleyin | CVE-2020-6168İstismar yok | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable webfactoryltd · minimal coming soon \& maintenance mode · CWE-862 | Yüksek7,6 | — | %2,0 | 9 Oca 2020 |
28İzleyin | CVE-2021-24142İstismar yok | 301 Redirects - Easy Redirect Manager < 2.51 - Authenticated SQL Injectionwebfactoryltd · 301 redirects · CWE-89 | Yüksek7,2 | — | %1,2 | 18 Mar 2021 |
28İzleyin | CVE-2023-50837İstismar yok | WordPress Login Lockdown Plugin <= 2.06 is vulnerable to SQL Injectionwebfactoryltd · wp login lockdown · CWE-89 | Yüksek7,2 | — | %0,6 | 29 Ara 2023 |
26İzleyin | CVE-2022-1583İstismar yok | External Links in New Window / New Tab < 1.43 - Tabnabbingwebfactoryltd · external links in new window \/ new tab · CWE-1022 | Orta6,5 | — | %1,3 | 30 May 2022 |
24İzleyin | CVE-2022-1582İstismar yok | External Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scriptingwebfactoryltd · external links in new window \/ new tab · CWE-79 | Orta6,1 | — | %0,8 | 30 May 2022 |
23İzleyin | CVE-2023-6799İstismar yok | WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomnesswebfactoryltd · wp reset · CWE-330 | Orta5,9 | — | %0,7 | 9 Nis 2024 |
21İzleyin | CVE-2020-6166İstismar yok | A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export webfactoryltd · minimal coming soon \& maintenance mode · CWE-276 | Orta5,4 | — | %1,1 | 9 Oca 2020 |
21İzleyin | CVE-2024-1075İstismar yok | Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypasswebfactoryltd · minimal coming soon \& maintenance mode · CWE-639 | Orta5,3 | — | %0,7 | 5 Şub 2024 |
21İzleyin | CVE-2021-24424İstismar yok | WP Reset < 1.90 - Authenticated Stored XSSwebfactoryltd · wp reset · CWE-79 | Orta5,4 | — | %0,6 | 12 Tem 2021 |
21İzleyin | CVE-2024-5087İstismar yok | Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Changewebfactoryltd · minimal coming soon \& maintenance mode · CWE-862 | Orta5,4 | — | %0,4 | 8 Haz 2024 |
21İzleyin | CVE-2024-1340İstismar yok | Login Lockdown – Protect Login Form <= 2.08 - Missing Authorizationwebfactoryltd · wp login lockdown · CWE-862 | Orta5,4 | — | %0,4 | 28 Şub 2024 |
21İzleyin | CVE-2023-49747İstismar yok | WordPress Guest Author Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS)webfactoryltd · guest author · CWE-79 | Orta5,4 | — | %0,4 | 15 Ara 2023 |
21İzleyin | CVE-2025-1262İstismar yok | Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypasswebfactoryltd · advanced google recaptcha · CWE-804 | Orta5,3 | — | %0,3 | 25 Şub 2025 |
19İzleyin | CVE-2021-24533İstismar yok | Maintenance < 4.03 - Authenticated Stored XSSwebfactoryltd · maintenance · CWE-79 | Orta4,8 | — | %0,6 | 23 Ağu 2021 |
19İzleyin | CVE-2023-1913İstismar yok | Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scriptingwebfactoryltd · maps widget for google maps · CWE-79 | Orta4,8 | — | %0,4 | 6 Nis 2023 |
18İzleyin | CVE-2024-1501İstismar yok | Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installationwebfactoryltd · wp database reset · CWE-352 | Orta4,7 | — | %0,3 | 21 Şub 2024 |
17İzleyin | CVE-2023-3601İstismar yok | Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDORwebfactoryltd · simple author box · CWE-639 | Orta4,3 | — | %0,5 | 14 Ağu 2023 |
17İzleyin | CVE-2024-5770İstismar yok | WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Updatewebfactoryltd · wp force ssl · CWE-862 | Orta4,3 | — | %0,3 | 8 Haz 2024 |
17İzleyin | CVE-2024-4661İstismar yok | WP Reset <= 2.02 - Missing Authorization to License Key Modificationwebfactoryltd · wp reset · CWE-862 | Orta4,3 | — | %0,3 | 8 Haz 2024 |
- CVE-2020-704843Planlayın
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the databas
KritikCVSS 9,1Kavram kanıtıEPSS %23webfactoryltd · wp database reset16 Oca 2020
- CVE-2020-704736İzleyin
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability
YüksekCVSS 8,8İstismar yokEPSS %2webfactoryltd · wp database reset16 Oca 2020
- CVE-2019-1991536İzleyin
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, del
KritikCVSS 9,0İstismar yokEPSS %1webfactoryltd · 301 redirects19 Ara 2019
- CVE-2020-616735İzleyin
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject
YüksekCVSS 8,8İstismar yokEPSS %1webfactoryltd · minimal coming soon \& maintenance mode9 Oca 2020
- CVE-2021-3690835İzleyin
WordPress WP Reset PRO Premium Plugin <= 5.98 - Cross-Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1webfactoryltd · wp reset pro18 Kas 2021
- CVE-2021-3690933İzleyin
WordPress WP Reset PRO Premium plugin <= 5.98 - Authenticated Database Reset vulnerability
YüksekCVSS 8,1İstismar yokEPSS %2webfactoryltd · wp reset pro18 Kas 2021
- CVE-2020-616831İzleyin
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable
YüksekCVSS 7,6İstismar yokEPSS %2webfactoryltd · minimal coming soon \& maintenance mode9 Oca 2020
- CVE-2021-2414228İzleyin
301 Redirects - Easy Redirect Manager < 2.51 - Authenticated SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1webfactoryltd · 301 redirects18 Mar 2021
- CVE-2023-5083728İzleyin
WordPress Login Lockdown Plugin <= 2.06 is vulnerable to SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1webfactoryltd · wp login lockdown29 Ara 2023
- CVE-2022-158326İzleyin
External Links in New Window / New Tab < 1.43 - Tabnabbing
OrtaCVSS 6,5İstismar yokEPSS %1webfactoryltd · external links in new window \/ new tab30 May 2022
- CVE-2022-158224İzleyin
External Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1webfactoryltd · external links in new window \/ new tab30 May 2022
- CVE-2023-679923İzleyin
WP Reset <= 2.0 - Sensitive Information Exposure due to Insufficient Randomness
OrtaCVSS 5,9İstismar yokEPSS %1webfactoryltd · wp reset9 Nis 2024
- CVE-2020-616621İzleyin
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export
OrtaCVSS 5,4İstismar yokEPSS %1webfactoryltd · minimal coming soon \& maintenance mode9 Oca 2020
- CVE-2024-107521İzleyin
Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass
OrtaCVSS 5,3İstismar yokEPSS %1webfactoryltd · minimal coming soon \& maintenance mode5 Şub 2024
- CVE-2021-2442421İzleyin
WP Reset < 1.90 - Authenticated Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %1webfactoryltd · wp reset12 Tem 2021
- CVE-2024-508721İzleyin
Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change
OrtaCVSS 5,4İstismar yokEPSS %0webfactoryltd · minimal coming soon \& maintenance mode8 Haz 2024
- CVE-2024-134021İzleyin
Login Lockdown – Protect Login Form <= 2.08 - Missing Authorization
OrtaCVSS 5,4İstismar yokEPSS %0webfactoryltd · wp login lockdown28 Şub 2024
- CVE-2023-4974721İzleyin
WordPress Guest Author Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0webfactoryltd · guest author15 Ara 2023
- CVE-2025-126221İzleyin
Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass
OrtaCVSS 5,3İstismar yokEPSS %0webfactoryltd · advanced google recaptcha25 Şub 2025
- CVE-2021-2453319İzleyin
Maintenance < 4.03 - Authenticated Stored XSS
OrtaCVSS 4,8İstismar yokEPSS %1webfactoryltd · maintenance23 Ağu 2021
- CVE-2023-191319İzleyin
Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scripting
OrtaCVSS 4,8İstismar yokEPSS %0webfactoryltd · maps widget for google maps6 Nis 2023
- CVE-2024-150118İzleyin
Database Reset <= 3.22 - Cross-Site Request Forgery to WP Reset Plugin Installation
OrtaCVSS 4,7İstismar yokEPSS %0webfactoryltd · wp database reset21 Şub 2024
- CVE-2023-360117İzleyin
Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDOR
OrtaCVSS 4,3İstismar yokEPSS %1webfactoryltd · simple author box14 Ağu 2023
- CVE-2024-577017İzleyin
WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Update
OrtaCVSS 4,3İstismar yokEPSS %0webfactoryltd · wp force ssl8 Haz 2024
- CVE-2024-466117İzleyin
WP Reset <= 2.02 - Missing Authorization to License Key Modification
OrtaCVSS 4,3İstismar yokEPSS %0webfactoryltd · wp reset8 Haz 2024