wpeverest kayıtları
wpeverest üreticisine ait 33 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %39,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-502 Deserialization of Untrusted Data4
- CWE-639 Authorization Bypass Through User-Controlled Key4
- CWE-862 Missing Authorization3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
33 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2025-1128İstismar yok | Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletionwpeverest · everest forms · CWE-434 | Kritik9,8 | — | %28,8 | 25 Şub 2025 |
47Planlayın | CVE-2025-2563Silahlaştırılmış | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalationwpeverest · user registration \& membership · CWE-639 | Yüksek8,1 | — | %48,8 | 14 Nis 2025 |
40Planlayın | CVE-2019-13575İstismar yok | A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9.wpeverest · everest forms · CWE-89 | Kritik9,8 | — | %2,6 | 18 Tem 2019 |
40Planlayın | CVE-2023-3342İstismar yok | User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Uploadwpeverest · user registration · CWE-434 | Kritik9,9 | — | %1,7 | 12 Tem 2023 |
39İzleyin | CVE-2025-3439İstismar yok | Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injectionwpeverest · everest forms · CWE-502 | Kritik9,8 | — | %1,2 | 11 Nis 2025 |
39İzleyin | CVE-2025-60210İstismar yok | WordPress Everest Forms - Frontend Listing plugin <= 1.0.5 - PHP Object Injection Vulnerabilitywpeverest · everest forms frontend listing · CWE-502 | Kritik9,8 | — | %0,5 | 22 Eki 2025 |
35İzleyin | CVE-2025-2594Kavram kanıtı | User Registration & Membership < 4.1.3 - Authentication Bypasswpeverest · user registration \& membership · CWE-639 | Yüksek8,1 | — | %9,4 | 22 Nis 2025 |
35İzleyin | CVE-2023-3343İstismar yok | User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injectionwpeverest · user registration · CWE-502 | Yüksek8,8 | — | %1,1 | 12 Tem 2023 |
35İzleyin | CVE-2024-2417İstismar yok | User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privwpeverest · user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login builder · CWE-862 | Yüksek8,8 | — | %0,9 | 2 May 2024 |
35İzleyin | CVE-2023-27459İstismar yok | WordPress User Registration plugin <= 2.3.2.1 - Authenticated PHP Object Injection vulnerabilitywpeverest · user registration \& membership · CWE-502 | Yüksek8,8 | — | %0,6 | 26 Mar 2024 |
30İzleyin | CVE-2022-3912İstismar yok | User Registration < 2.2.4.1 - Subscriber+ Arbitrary File Uploadwpeverest · user registration · CWE-434 | Yüksek7,5 | — | %0,8 | 12 Ara 2022 |
30İzleyin | CVE-2025-5927İstismar yok | Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletionwpeverest · everest forms · CWE-36 | Yüksek7,5 | — | %0,7 | 25 Haz 2025 |
28İzleyin | CVE-2024-1812İstismar yok | Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_urlwpeverest · everest forms · CWE-918 | Yüksek7,2 | — | %0,5 | 9 Nis 2024 |
25İzleyin | CVE-2025-3422İstismar yok | Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Executionwpeverest · everest forms · CWE-94 | Orta6,3 | — | %0,3 | 11 Nis 2025 |
24İzleyin | CVE-2021-24907İstismar yok | Everest Forms < 1.8.0 - Reflected Cross-Site Scriptingwpeverest · everest forms · CWE-79 | Orta6,1 | — | %0,9 | 21 Ara 2021 |
24İzleyin | CVE-2024-1720İstismar yok | User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scriptingwpeverest · user registration \& membership · CWE-79 | Orta6,1 | — | %0,5 | 7 Mar 2024 |
24İzleyin | CVE-2025-3421İstismar yok | Everest Forms <= 3.1.1 - Reflected Cross-Site Scriptingwpeverest · everest forms · CWE-79 | Orta6,1 | — | %0,4 | 11 Nis 2025 |
24İzleyin | CVE-2025-1511İstismar yok | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scriptingwpeverest · user registration · CWE-79 | Orta6,1 | — | %0,3 | 28 Şub 2025 |
24İzleyin | CVE-2025-39400İstismar yok | WordPress User Registration plugin < 4.2.0 - Reflected Cross Site Scripting (XSS) vulnerabilitywpeverest · user registration \& membership · CWE-79 | Orta6,1 | — | %0,3 | 24 Nis 2025 |
24İzleyin | CVE-2025-26841İstismar yok | Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.wpeverest · everest forms · CWE-79 | Orta6,1 | — | %0,3 | 12 May 2025 |
21İzleyin | CVE-2021-24654İstismar yok | User Registration < 2.0.2 - Low Privilege Stored Cross-Site Scriptingwpeverest · user registration · CWE-79 | Orta5,4 | — | %0,6 | 4 Eki 2021 |
21İzleyin | CVE-2023-29429İstismar yok | WordPress User Registration plugin <= 2.3.2.1 - Broken Access Control vulnerabilitywpeverest · user registration · CWE-862 | Orta5,3 | — | %0,4 | 9 Ara 2024 |
21İzleyin | CVE-2023-51377İstismar yok | WordPress Everest Forms plugin <= 2.0.3 - Broken Access Control vulnerabilitywpeverest · everest forms · CWE-862 | Orta5,3 | — | %0,3 | 14 Haz 2024 |
21İzleyin | CVE-2025-3282İstismar yok | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membershiwpeverest · user registration \& membership · CWE-639 | Orta5,3 | — | %0,3 | 12 Nis 2025 |
19İzleyin | CVE-2021-24689İstismar yok | Contact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Admin+ Arbitrary System File Readwpeverest · contact form · CWE-22 | Orta4,9 | — | %1,3 | 28 Şub 2022 |
- CVE-2025-112848Planlayın
Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion
KritikCVSS 9,8İstismar yokEPSS %29wpeverest · everest forms25 Şub 2025
- CVE-2025-256347Planlayın
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
YüksekCVSS 8,1SilahlaştırılmışEPSS %49wpeverest · user registration \& membership14 Nis 2025
- CVE-2019-1357540Planlayın
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9.
KritikCVSS 9,8İstismar yokEPSS %3wpeverest · everest forms18 Tem 2019
- CVE-2023-334240Planlayın
User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload
KritikCVSS 9,9İstismar yokEPSS %2wpeverest · user registration12 Tem 2023
- CVE-2025-343939İzleyin
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %1wpeverest · everest forms11 Nis 2025
- CVE-2025-6021039İzleyin
WordPress Everest Forms - Frontend Listing plugin <= 1.0.5 - PHP Object Injection Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1wpeverest · everest forms frontend listing22 Eki 2025
- CVE-2025-259435İzleyin
User Registration & Membership < 4.1.3 - Authentication Bypass
YüksekCVSS 8,1Kavram kanıtıEPSS %9wpeverest · user registration \& membership22 Nis 2025
- CVE-2023-334335İzleyin
User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection
YüksekCVSS 8,8İstismar yokEPSS %1wpeverest · user registration12 Tem 2023
- CVE-2024-241735İzleyin
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Priv
YüksekCVSS 8,8İstismar yokEPSS %1wpeverest · user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login builder2 May 2024
- CVE-2023-2745935İzleyin
WordPress User Registration plugin <= 2.3.2.1 - Authenticated PHP Object Injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1wpeverest · user registration \& membership26 Mar 2024
- CVE-2022-391230İzleyin
User Registration < 2.2.4.1 - Subscriber+ Arbitrary File Upload
YüksekCVSS 7,5İstismar yokEPSS %1wpeverest · user registration12 Ara 2022
- CVE-2025-592730İzleyin
Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion
YüksekCVSS 7,5İstismar yokEPSS %1wpeverest · everest forms25 Haz 2025
- CVE-2024-181228İzleyin
Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url
YüksekCVSS 7,2İstismar yokEPSS %1wpeverest · everest forms9 Nis 2024
- CVE-2025-342225İzleyin
Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
OrtaCVSS 6,3İstismar yokEPSS %0wpeverest · everest forms11 Nis 2025
- CVE-2021-2490724İzleyin
Everest Forms < 1.8.0 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1wpeverest · everest forms21 Ara 2021
- CVE-2024-172024İzleyin
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %1wpeverest · user registration \& membership7 Mar 2024
- CVE-2025-342124İzleyin
Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpeverest · everest forms11 Nis 2025
- CVE-2025-151124İzleyin
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0wpeverest · user registration28 Şub 2025
- CVE-2025-3940024İzleyin
WordPress User Registration plugin < 4.2.0 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0wpeverest · user registration \& membership24 Nis 2025
- CVE-2025-2684124İzleyin
Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.
OrtaCVSS 6,1İstismar yokEPSS %0wpeverest · everest forms12 May 2025
- CVE-2021-2465421İzleyin
User Registration < 2.0.2 - Low Privilege Stored Cross-Site Scripting
OrtaCVSS 5,4İstismar yokEPSS %1wpeverest · user registration4 Eki 2021
- CVE-2023-2942921İzleyin
WordPress User Registration plugin <= 2.3.2.1 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0wpeverest · user registration9 Ara 2024
- CVE-2023-5137721İzleyin
WordPress Everest Forms plugin <= 2.0.3 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0wpeverest · everest forms14 Haz 2024
- CVE-2025-328221İzleyin
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membershi
OrtaCVSS 5,3İstismar yokEPSS %0wpeverest · user registration \& membership12 Nis 2025
- CVE-2021-2468919İzleyin
Contact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Admin+ Arbitrary System File Read
OrtaCVSS 4,9İstismar yokEPSS %1wpeverest · contact form28 Şub 2022