WebToffee kayıtları
webtoffee üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %40
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-862 Missing Authorization6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File4
- CWE-918 Server-Side Request Forgery (SSRF)3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-3162İstismar yok | Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypasswebtoffee · stripe payment plugin for woocommerce · CWE-288 | Kritik9,8 | — | %1,2 | 31 Ağu 2023 |
39İzleyin | CVE-2022-45370İstismar yok | WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injectionwebtoffee · wordpress comments import and export · CWE-1236 | Kritik9,8 | — | %0,8 | 7 Kas 2023 |
39İzleyin | CVE-2022-46802İstismar yok | WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injectionwebtoffee · product reviews import export for woocommerce · CWE-1236 | Kritik9,8 | — | %0,7 | 7 Kas 2023 |
36İzleyin | CVE-2020-12074İstismar yok | The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts webtoffee · import export wordpress users · CWE-269 | Yüksek8,8 | — | %1,7 | 22 Nis 2020 |
35İzleyin | CVE-2023-48284İstismar yok | WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)webtoffee · decorator · CWE-352 | Yüksek8,8 | — | %0,3 | 30 Kas 2023 |
33İzleyin | CVE-2018-11526Kavram kanıtı | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.webtoffee · wordpress comments import and export · CWE-1236 | Yüksek7,8 | — | %5,1 | 19 Haz 2018 |
31İzleyin | CVE-2019-15092Kavram kanıtı | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displwebtoffee · import export wordpress users · CWE-1236 | Yüksek7,3 | — | %5,1 | 23 Ağu 2019 |
31İzleyin | CVE-2024-0705Kavram kanıtı | Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injectionwebtoffee · stripe payment plugin for woocommerce · CWE-89 | Yüksek7,5 | — | %2,6 | 19 Oca 2024 |
30İzleyin | CVE-2024-31254İstismar yok | WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerabilitywebtoffee · backup and migration · CWE-532 | Yüksek7,5 | — | %0,5 | 10 Nis 2024 |
30İzleyin | CVE-2025-1970İstismar yok | Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Functionwebtoffee · import export wordpress users · CWE-918 | Yüksek7,6 | — | %0,4 | 22 Mar 2025 |
30İzleyin | CVE-2025-1912İstismar yok | Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Functionwebtoffee · product import export for woocommerce · CWE-918 | Yüksek7,6 | — | %0,4 | 26 Mar 2025 |
28İzleyin | CVE-2023-6558İstismar yok | Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Uploadwebtoffee · import export wordpress users · CWE-434 | Yüksek7,2 | — | %1,4 | 11 Oca 2024 |
28İzleyin | CVE-2023-3459İstismar yok | Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Changewebtoffee · import export wordpress users · CWE-863 | Yüksek7,2 | — | %0,9 | 17 Tem 2023 |
28İzleyin | CVE-2025-1913Kavram kanıtı | Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameterwebtoffee · product import export for woocommerce · CWE-502 | Yüksek7,2 | — | %0,9 | 26 Mar 2025 |
28İzleyin | CVE-2025-1971İstismar yok | Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameterwebtoffee · import export wordpress users · CWE-502 | Yüksek7,2 | — | %0,8 | 22 Mar 2025 |
28İzleyin | CVE-2024-13921İstismar yok | Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameterwebtoffee · order export \& order import for woocommerce · CWE-502 | Yüksek7,2 | — | %0,7 | 20 Mar 2025 |
28İzleyin | CVE-2023-51546İstismar yok | WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerabilitywebtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels · CWE-269 | Yüksek7,2 | — | %0,6 | 17 May 2024 |
28İzleyin | CVE-2024-30231İstismar yok | WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerabilitywebtoffee · product import export for woocommerce · CWE-434 | Yüksek7,2 | — | %0,6 | 26 Mar 2024 |
28İzleyin | CVE-2024-22135İstismar yok | WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Uploadwebtoffee · order export \& order import for woocommerce · CWE-434 | Yüksek7,2 | — | %0,5 | 24 Oca 2024 |
28İzleyin | CVE-2024-22152İstismar yok | WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Uploadwebtoffee · product import export for woocommerce · CWE-434 | Yüksek7,2 | — | %0,5 | 24 Oca 2024 |
26İzleyin | CVE-2025-1911İstismar yok | Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functiwebtoffee · product import export for woocommerce · CWE-73 | Orta6,5 | — | %0,4 | 26 Mar 2025 |
26İzleyin | CVE-2025-1972İstismar yok | Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functiwebtoffee · import export wordpress users · CWE-73 | Orta6,5 | — | %0,4 | 22 Mar 2025 |
26İzleyin | CVE-2024-13922İstismar yok | Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page webtoffee · order export \& order import for woocommerce · CWE-73 | Orta6,5 | — | %0,4 | 20 Mar 2025 |
26İzleyin | CVE-2024-13923İstismar yok | Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Functionwebtoffee · order export \& order import for woocommerce · CWE-918 | Orta6,5 | — | %0,4 | 20 Mar 2025 |
26İzleyin | CVE-2023-7068İstismar yok | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Exportwebtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels · CWE-862 | Orta6,5 | — | %0,4 | 3 Oca 2024 |
- CVE-2023-316239İzleyin
Stripe Payment Plugin for WooCommerce <= 3.7.7 - Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %1webtoffee · stripe payment plugin for woocommerce31 Ağu 2023
- CVE-2022-4537039İzleyin
WordPress WordPress Comments Import & Export Plugin <= 2.3.1 is vulnerable to CSV Injection
KritikCVSS 9,8İstismar yokEPSS %1webtoffee · wordpress comments import and export7 Kas 2023
- CVE-2022-4680239İzleyin
WordPress Product Reviews Import Export for WooCommerce Plugin <= 1.4.8 is vulnerable to CSV Injection
KritikCVSS 9,8İstismar yokEPSS %1webtoffee · product reviews import export for woocommerce7 Kas 2023
- CVE-2020-1207436İzleyin
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts
YüksekCVSS 8,8İstismar yokEPSS %2webtoffee · import export wordpress users22 Nis 2020
- CVE-2023-4828435İzleyin
WordPress Decorator – WooCommerce Email Customizer Plugin <= 1.2.7 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0webtoffee · decorator30 Kas 2023
- CVE-2018-1152633İzleyin
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
YüksekCVSS 7,8Kavram kanıtıEPSS %5webtoffee · wordpress comments import and export19 Haz 2018
- CVE-2019-1509231İzleyin
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, displ
YüksekCVSS 7,3Kavram kanıtıEPSS %5webtoffee · import export wordpress users23 Ağu 2019
- CVE-2024-070531İzleyin
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
YüksekCVSS 7,5Kavram kanıtıEPSS %3webtoffee · stripe payment plugin for woocommerce19 Oca 2024
- CVE-2024-3125430İzleyin
WordPress WordPress Backup & Migration plugin <= 1.4.7 - Sensitive Data Exposure via Log File vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0webtoffee · backup and migration10 Nis 2024
- CVE-2025-197030İzleyin
Export and Import Users and Customers <= 2.6.2 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
YüksekCVSS 7,6İstismar yokEPSS %0webtoffee · import export wordpress users22 Mar 2025
- CVE-2025-191230İzleyin
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
YüksekCVSS 7,6İstismar yokEPSS %0webtoffee · product import export for woocommerce26 Mar 2025
- CVE-2023-655828İzleyin
Export and Import Users and Customers <= 2.4.8 - Authenticated (Shop Manager+) Arbitrary File Upload
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · import export wordpress users11 Oca 2024
- CVE-2023-345928İzleyin
Export and Import Users and Customers <= 2.4.1 - Missing Authorization to Authenticated (Shop Manager) Arbitrary User Password Change
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · import export wordpress users17 Tem 2023
- CVE-2025-191328İzleyin
Product Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
YüksekCVSS 7,2Kavram kanıtıEPSS %1webtoffee · product import export for woocommerce26 Mar 2025
- CVE-2025-197128İzleyin
Export and Import Users and Customers <= 2.6.2 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · import export wordpress users22 Mar 2025
- CVE-2024-1392128İzleyin
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · order export \& order import for woocommerce20 Mar 2025
- CVE-2023-5154628İzleyin
WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels17 May 2024
- CVE-2024-3023128İzleyin
WordPress Product Import Export for WooCommerce plugin <= 2.4.1 - Arbitrary File Upload vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · product import export for woocommerce26 Mar 2024
- CVE-2024-2213528İzleyin
WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · order export \& order import for woocommerce24 Oca 2024
- CVE-2024-2215228İzleyin
WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload
YüksekCVSS 7,2İstismar yokEPSS %1webtoffee · product import export for woocommerce24 Oca 2024
- CVE-2025-191126İzleyin
Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi
OrtaCVSS 6,5İstismar yokEPSS %0webtoffee · product import export for woocommerce26 Mar 2025
- CVE-2025-197226İzleyin
Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Functi
OrtaCVSS 6,5İstismar yokEPSS %0webtoffee · import export wordpress users22 Mar 2025
- CVE-2024-1392226İzleyin
Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page
OrtaCVSS 6,5İstismar yokEPSS %0webtoffee · order export \& order import for woocommerce20 Mar 2025
- CVE-2024-1392326İzleyin
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function
OrtaCVSS 6,5İstismar yokEPSS %0webtoffee · order export \& order import for woocommerce20 Mar 2025
- CVE-2023-706826İzleyin
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 - Missing Authorization to Order Export
OrtaCVSS 6,5İstismar yokEPSS %0webtoffee · woocommerce pdf invoices\, packing slips\, delivery notes and shipping labels3 Oca 2024