wpsupportplus kayıtları
wpsupportplus üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %11,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-20 Improper Input Validation1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2014-10389İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.wpsupportplus · wp support plus responsive ticket system · CWE-287 | Kritik9,8 | — | %2,2 | 22 Ağu 2019 |
40Planlayın | CVE-2018-1000131İstismar yok | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the functwpsupportplus · wp support plus responsive ticket system · CWE-89 | Kritik9,8 | — | %2,1 | 14 Mar 2018 |
40Planlayın | CVE-2016-10930İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.wpsupportplus · wp support plus responsive ticket system · CWE-20 | Kritik9,8 | — | %2,0 | 22 Ağu 2019 |
40Planlayın | CVE-2014-10387İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.wpsupportplus · wp support plus responsive ticket system · CWE-89 | Kritik9,8 | — | %1,8 | 22 Ağu 2019 |
37İzleyin | CVE-2014-10390İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.wpsupportplus · wp support plus responsive ticket system · CWE-22 | Kritik9,1 | — | %2,5 | 22 Ağu 2019 |
24İzleyin | CVE-2019-7299İstismar yok | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1wpsupportplus · wp support plus responsive ticket system · CWE-79 | Orta6,1 | — | %1,7 | 21 Mar 2019 |
24İzleyin | CVE-2014-10391İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.wpsupportplus · wp support plus responsive ticket system · CWE-74 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
24İzleyin | CVE-2019-15331İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.wpsupportplus · wp support plus responsive ticket system · CWE-79 | Orta6,1 | — | %0,9 | 22 Ağu 2019 |
21İzleyin | CVE-2014-10388İstismar yok | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.wpsupportplus · wp support plus responsive ticket system · CWE-200 | Orta5,3 | — | %1,3 | 22 Ağu 2019 |
- CVE-2014-1038940Planlayın
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
KritikCVSS 9,8İstismar yokEPSS %2wpsupportplus · wp support plus responsive ticket system22 Ağu 2019
- CVE-2018-100013140Planlayın
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the funct
KritikCVSS 9,8İstismar yokEPSS %2wpsupportplus · wp support plus responsive ticket system14 Mar 2018
- CVE-2016-1093040Planlayın
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
KritikCVSS 9,8İstismar yokEPSS %2wpsupportplus · wp support plus responsive ticket system22 Ağu 2019
- CVE-2014-1038740Planlayın
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
KritikCVSS 9,8İstismar yokEPSS %2wpsupportplus · wp support plus responsive ticket system22 Ağu 2019
- CVE-2014-1039037İzleyin
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
KritikCVSS 9,1İstismar yokEPSS %3wpsupportplus · wp support plus responsive ticket system22 Ağu 2019
- CVE-2019-729924İzleyin
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1
OrtaCVSS 6,1İstismar yokEPSS %2wpsupportplus · wp support plus responsive ticket system21 Mar 2019
- CVE-2014-1039124İzleyin
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
OrtaCVSS 6,1İstismar yokEPSS %1wpsupportplus · wp support plus responsive ticket system22 Ağu 2019
- CVE-2019-1533124İzleyin
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
OrtaCVSS 6,1İstismar yokEPSS %1wpsupportplus · wp support plus responsive ticket system22 Ağu 2019
- CVE-2014-1038821İzleyin
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
OrtaCVSS 5,3İstismar yokEPSS %1wpsupportplus · wp support plus responsive ticket system22 Ağu 2019