WPML kayıtları
wpml üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-284 Improper Access Control1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2024-6386Kavram kanıtı | WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injectionwpml · wpml · CWE-1336 | Yüksek8,8 | — | %25,5 | 21 Ağu 2024 |
35İzleyin | CVE-2022-45071İstismar yok | WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerabilitywpml · wpml · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Kas 2022 |
32İzleyin | CVE-2015-2314Kavram kanıtı | SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the wpml · wpml · CWE-89 | Yüksek7,5 | — | %7,1 | 17 Mar 2015 |
31İzleyin | CVE-2015-2792İstismar yok | The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nwpml · wpml · CWE-284 | Yüksek7,5 | — | %3,8 | 30 Mar 2015 |
29İzleyin | CVE-2015-2791Kavram kanıtı | The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus vwpml · wpml · CWE-264 | Orta6,4 | — | %13,3 | 30 Mar 2015 |
28İzleyin | CVE-2018-18069Kavram kanıtı | process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (swpml · wpml · CWE-79 | Orta6,1 | — | %13,2 | 8 Eki 2018 |
21İzleyin | CVE-2025-3488İstismar yok | WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcodewpml · wpml · CWE-79 | Orta5,4 | — | %0,3 | 2 May 2025 |
19İzleyin | CVE-2015-2315Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web scripwpml · wpml · CWE-79 | Orta4,3 | — | %7,0 | 17 Mar 2015 |
17İzleyin | CVE-2022-38974İstismar yok | WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerabilitywpml · wpml · CWE-264 | Orta4,3 | — | %0,5 | 18 Kas 2022 |
17İzleyin | CVE-2022-38461İstismar yok | WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerabilitywpml · wpml · CWE-264 | Orta4,3 | — | %0,5 | 17 Kas 2022 |
17İzleyin | CVE-2022-45072İstismar yok | WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerabilitywpml · wpml · CWE-352 | Orta4,3 | — | %0,3 | 17 Kas 2022 |
- CVE-2024-638643Planlayın
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
YüksekCVSS 8,8Kavram kanıtıEPSS %26wpml · wpml21 Ağu 2024
- CVE-2022-4507135İzleyin
WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0wpml · wpml17 Kas 2022
- CVE-2015-231432İzleyin
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %7wpml · wpml17 Mar 2015
- CVE-2015-279231İzleyin
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass n
YüksekCVSS 7,5İstismar yokEPSS %4wpml · wpml30 Mar 2015
- CVE-2015-279129İzleyin
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus v
OrtaCVSS 6,4Kavram kanıtıEPSS %13wpml · wpml30 Mar 2015
- CVE-2018-1806928İzleyin
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (s
OrtaCVSS 6,1Kavram kanıtıEPSS %13wpml · wpml8 Eki 2018
- CVE-2025-348821İzleyin
WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode
OrtaCVSS 5,4İstismar yokEPSS %0wpml · wpml2 May 2025
- CVE-2015-231519İzleyin
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web scrip
OrtaCVSS 4,3Kavram kanıtıEPSS %7wpml · wpml17 Mar 2015
- CVE-2022-3897417İzleyin
WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability
OrtaCVSS 4,3İstismar yokEPSS %1wpml · wpml18 Kas 2022
- CVE-2022-3846117İzleyin
WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability
OrtaCVSS 4,3İstismar yokEPSS %1wpml · wpml17 Kas 2022
- CVE-2022-4507217İzleyin
WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability
OrtaCVSS 4,3İstismar yokEPSS %0wpml · wpml17 Kas 2022