wpchill kayıtları
wpchill üreticisine ait 47 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %27,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
47 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2021-23174İstismar yok | WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilitywpchill · download monitor · CWE-79 | Orta4,8 | — | %83,9 | 28 Oca 2022 |
41Planlayın | CVE-2022-45354Kavram kanıtı | WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposurewpchill · download monitor · CWE-200 | Yüksek7,5 | — | %38,1 | 8 Oca 2024 |
35İzleyin | CVE-2023-34007İstismar yok | WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Uploadwpchill · download monitor · CWE-434 | Yüksek8,8 | — | %0,9 | 20 Ara 2023 |
35İzleyin | CVE-2024-12853İstismar yok | Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Uploadwpchill · modula image gallery · CWE-434 | Yüksek8,8 | — | %0,9 | 8 Oca 2025 |
35İzleyin | CVE-2024-47362İstismar yok | WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerabilitywpchill · strong testimonials · CWE-862 | Yüksek8,8 | — | %0,4 | 1 Kas 2024 |
35İzleyin | CVE-2024-49256İstismar yok | WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerabilitywpchill · htaccess file editor · CWE-863 | Yüksek8,8 | — | %0,4 | 1 Kas 2024 |
35İzleyin | CVE-2022-36292İstismar yok | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilitieswpchill · gallery photoblocks · CWE-352 | Yüksek8,8 | — | %0,4 | 23 Ağu 2022 |
35İzleyin | CVE-2023-52123İstismar yok | WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)wpchill · strong testimonials · CWE-352 | Yüksek8,8 | — | %0,2 | 5 Oca 2024 |
33İzleyin | CVE-2021-24786Kavram kanıtı | Download Monitor < 4.4.5 - Admin+ SQL Injectionwpchill · download monitor · CWE-89 | Yüksek7,2 | — | %17,3 | 3 Oca 2022 |
30İzleyin | CVE-2022-4972İstismar yok | Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Exportwpchill · download monitor · CWE-862 | Yüksek7,5 | — | %0,5 | 16 Eki 2024 |
30İzleyin | CVE-2024-11282İstismar yok | Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposurewpchill · passster · CWE-200 | Yüksek7,5 | — | %0,4 | 7 Oca 2025 |
28İzleyin | CVE-2021-24774İstismar yok | Check & Log Email < 1.0.3 - Admin+ SQL Injectionswpchill · check \& log email · CWE-89 | Yüksek7,2 | — | %1,3 | 25 Eki 2021 |
28İzleyin | CVE-2025-13645İstismar yok | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletionwpchill · modula image gallery · CWE-22 | Yüksek7,2 | — | %1,0 | 2 Ara 2025 |
28İzleyin | CVE-2024-30501İstismar yok | WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerabilitywpchill · download monitor · CWE-89 | Yüksek7,2 | — | %0,6 | 29 Mar 2024 |
27İzleyin | CVE-2021-31567İstismar yok | WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerabilitywpchill · download monitor · CWE-200 | Orta6,8 | — | %1,4 | 28 Oca 2022 |
27İzleyin | CVE-2024-3710İstismar yok | Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSSwpchill · image photo gallery final tiles grid · CWE-79 | Orta6,8 | — | %0,5 | 13 Tem 2024 |
26İzleyin | CVE-2025-13646İstismar yok | Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Conditionwpchill · modula image gallery · CWE-434 | Orta6,6 | — | %0,8 | 2 Ara 2025 |
25İzleyin | CVE-2020-8549İstismar yok | Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as steawpchill · strong testimonials · CWE-79 | Orta6,1 | — | %1,9 | 3 Şub 2020 |
24İzleyin | CVE-2022-1547İstismar yok | Check & Log email < 1.0.6 - Reflected Cross-Site Scriptingwpchill · check \& log email · CWE-79 | Orta6,1 | — | %0,8 | 23 May 2022 |
24İzleyin | CVE-2021-24908İstismar yok | Check & Log Email < 1.0.4 - Reflected Cross-Site Scriptingwpchill · check \& log email · CWE-79 | Orta6,1 | — | %0,8 | 29 Kas 2021 |
24İzleyin | CVE-2022-27852İstismar yok | WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilitieswpchill · kb support · CWE-79 | Orta6,1 | — | %0,7 | 15 Nis 2022 |
22İzleyin | CVE-2022-1054Kavram kanıtı | RSVP and Event Management < 2.7.8 - Unauthenticated Entries Exportwpchill · rsvp and event management · CWE-862 | Orta5,3 | — | %4,2 | 18 Nis 2022 |
21İzleyin | CVE-2020-9003İstismar yok | A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.wpchill · modula image gallery · CWE-79 | Orta5,4 | — | %1,0 | 20 Şub 2020 |
21İzleyin | CVE-2022-37407İstismar yok | WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswpchill · gallery photoblocks · CWE-79 | Orta5,4 | — | %0,6 | 9 Eyl 2022 |
21İzleyin | CVE-2021-36920İstismar yok | WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilitywpchill · download monitor · CWE-79 | Orta5,4 | — | %0,6 | 14 Oca 2022 |
- CVE-2021-2317444Planlayın
WordPress Download Monitor plugin <= 4.4.6 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
OrtaCVSS 4,8İstismar yokEPSS %84wpchill · download monitor28 Oca 2022
- CVE-2022-4535441Planlayın
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
YüksekCVSS 7,5Kavram kanıtıEPSS %38wpchill · download monitor8 Oca 2024
- CVE-2023-3400735İzleyin
WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1wpchill · download monitor20 Ara 2023
- CVE-2024-1285335İzleyin
Modula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1wpchill · modula image gallery8 Oca 2025
- CVE-2024-4736235İzleyin
WordPress Strong Testimonials plugin <= 3.1.16 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0wpchill · strong testimonials1 Kas 2024
- CVE-2024-4925635İzleyin
WordPress Htaccess File Editor plugin <= 1.0.18 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0wpchill · htaccess file editor1 Kas 2024
- CVE-2022-3629235İzleyin
WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilities
YüksekCVSS 8,8İstismar yokEPSS %0wpchill · gallery photoblocks23 Ağu 2022
- CVE-2023-5212335İzleyin
WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0wpchill · strong testimonials5 Oca 2024
- CVE-2021-2478633İzleyin
Download Monitor < 4.4.5 - Admin+ SQL Injection
YüksekCVSS 7,2Kavram kanıtıEPSS %17wpchill · download monitor3 Oca 2022
- CVE-2022-497230İzleyin
Download Monitor <= 4.7.51 - Missing Authorization to Unauthenticated Data Export
YüksekCVSS 7,5İstismar yokEPSS %0wpchill · download monitor16 Eki 2024
- CVE-2024-1128230İzleyin
Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
YüksekCVSS 7,5İstismar yokEPSS %0wpchill · passster7 Oca 2025
- CVE-2021-2477428İzleyin
Check & Log Email < 1.0.3 - Admin+ SQL Injections
YüksekCVSS 7,2İstismar yokEPSS %1wpchill · check \& log email25 Eki 2021
- CVE-2025-1364528İzleyin
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion
YüksekCVSS 7,2İstismar yokEPSS %1wpchill · modula image gallery2 Ara 2025
- CVE-2024-3050128İzleyin
WordPress Download Monitor theme <= 4.9.4 - Auth. SQL Injection vulnerability
YüksekCVSS 7,2İstismar yokEPSS %1wpchill · download monitor29 Mar 2024
- CVE-2021-3156727İzleyin
WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnerability
OrtaCVSS 6,8İstismar yokEPSS %1wpchill · download monitor28 Oca 2022
- CVE-2024-371027İzleyin
Image Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS
OrtaCVSS 6,8İstismar yokEPSS %0wpchill · image photo gallery final tiles grid13 Tem 2024
- CVE-2025-1364626İzleyin
Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition
OrtaCVSS 6,6İstismar yokEPSS %1wpchill · modula image gallery2 Ara 2025
- CVE-2020-854925İzleyin
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stea
OrtaCVSS 6,1İstismar yokEPSS %2wpchill · strong testimonials3 Şub 2020
- CVE-2022-154724İzleyin
Check & Log email < 1.0.6 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1wpchill · check \& log email23 May 2022
- CVE-2021-2490824İzleyin
Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1wpchill · check \& log email29 Kas 2021
- CVE-2022-2785224İzleyin
WordPress KB Support plugin <= 1.5.5 - Multiple Unauth. Stored Cross-Site Scripting (XSS) vulnerabilities
OrtaCVSS 6,1İstismar yokEPSS %1wpchill · kb support15 Nis 2022
- CVE-2022-105422İzleyin
RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export
OrtaCVSS 5,3Kavram kanıtıEPSS %4wpchill · rsvp and event management18 Nis 2022
- CVE-2020-900321İzleyin
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress.
OrtaCVSS 5,4İstismar yokEPSS %1wpchill · modula image gallery20 Şub 2020
- CVE-2022-3740721İzleyin
WordPress Gallery PhotoBlocks plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
OrtaCVSS 5,4İstismar yokEPSS %1wpchill · gallery photoblocks9 Eyl 2022
- CVE-2021-3692021İzleyin
WordPress plugin Download Monitor <= 4.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
OrtaCVSS 5,4İstismar yokEPSS %1wpchill · download monitor14 Oca 2022