İçeriğe atla
Noroxi

wpengine kayıtları

wpengine üreticisine ait 13 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%46,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

13 kayıt
  • CVE-2023-6933
    55Planlayın

    Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection

    YüksekCVSS 8,8Kavram kanıtıEPSS %68

    wpengine · better search replace5 Şub 2024

  • CVE-2019-9879
    53Planlayın

    The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registratio

    KritikCVSS 9,8Kavram kanıtıEPSS %47

    wpengine · wpgraphql10 Haz 2019

  • CVE-2019-9880
    46Planlayın

    An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress.

    KritikCVSS 9,1Kavram kanıtıEPSS %35

    wpengine · wpgraphql10 Haz 2019

  • CVE-2024-30225
    40Planlayın

    WordPress WP Migrate plugin <= 2.6.10 - Unauthenticated PHP Object Injection vulnerability

    KritikCVSS 10,0İstismar yokEPSS %1

    wpengine, inc. · wp migrate28 Mar 2024

  • CVE-2024-34762
    39İzleyin

    Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability

    KritikCVSS 9,9İstismar yokEPSS %1

    wpengine inc · advanced custom fields pro10 Haz 2024

  • CVE-2023-24421
    35İzleyin

    WordPress PHP Compatibility Checker Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF)

    YüksekCVSS 8,8İstismar yokEPSS %0

    wpengine · php compatibility checker11 Tem 2023

  • CVE-2019-9881
    27İzleyin

    The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even wh

    OrtaCVSS 5,3Kavram kanıtıEPSS %19

    wpengine · wpgraphql10 Haz 2019

  • CVE-2024-2761
    27İzleyin

    Genesis Blocks < 3.1.3 - Contributor+ Stored XSS

    OrtaCVSS 6,8İstismar yokEPSS %1

    wpengine · genesis blocks19 Nis 2024

  • CVE-2024-3901
    27İzleyin

    Genesis Blocks <= 3.1.3 - Contributor+ Stored XSS

    OrtaCVSS 6,8İstismar yokEPSS %1

    wpengine · genesis blocks15 May 2025

  • CVE-2023-23684
    26İzleyin

    WordPress WPGraphQL Plugin <= 1.14.5 is vulnerable to Server Side Request Forgery (SSRF)

    OrtaCVSS 6,5İstismar yokEPSS %0

    wpengine · wpgraphql12 Kas 2023

  • CVE-2024-45429
    24İzleyin

    Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5

    OrtaCVSS 6,1İstismar yokEPSS %0

    wpengine · advanced custom fields4 Eyl 2024

  • CVE-2022-1563
    21İzleyin

    WPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure

    OrtaCVSS 5,3İstismar yokEPSS %1

    wpengine · wpgraphql16 Oca 2024

  • CVE-2024-3563
    21İzleyin

    Genesis Blocks <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributes

    OrtaCVSS 5,4İstismar yokEPSS %0

    wpengine · genesis blocks9 Tem 2024