XTENDIFY kayıtları
xtendify üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %41,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-269 Improper Privilege Management1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-43234İstismar yok | WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerabilityxtendify · woffice · CWE-288 | Kritik9,8 | — | %0,7 | 16 Ara 2024 |
39İzleyin | CVE-2025-2798İstismar yok | Woffice <= 5.4.21 - Authentication Bypass via Registration Rolextendify · woffice · CWE-269 | Kritik9,8 | — | %0,7 | 4 Nis 2025 |
39İzleyin | CVE-2024-43153İstismar yok | WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerabilityxtendify · woffice · CWE-266 | Kritik9,8 | — | %0,6 | 13 Ağu 2024 |
39İzleyin | CVE-2024-37470İstismar yok | WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerabilityxtendify · woffice · CWE-862 | Kritik9,8 | — | %0,5 | 1 Kas 2024 |
35İzleyin | CVE-2025-2780İstismar yok | Woffice Core <= 5.4.21 - Authenticated (Subscriber+) Arbitrary File Uploadxtendify · woffice · CWE-434 | Yüksek8,8 | — | %0,8 | 4 Nis 2025 |
35İzleyin | CVE-2023-46189İstismar yok | WordPress Google Calendar Events Plugin <= 3.2.5 is vulnerable to Cross Site Request Forgery (CSRF)xtendify · simple calendar · CWE-352 | Yüksek8,8 | — | %0,3 | 25 Eki 2023 |
30İzleyin | CVE-2025-7694İstismar yok | Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletionxtendify · woffice · CWE-22 | Yüksek7,5 | — | %0,9 | 2 Ağu 2025 |
24İzleyin | CVE-2024-8549İstismar yok | Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scriptingxtendify · simple calendar · CWE-79 | Orta6,1 | — | %0,5 | 24 Eyl 2024 |
24İzleyin | CVE-2024-37472İstismar yok | WordPress Woffice theme <= 5.4.8 - Reflected Cross Site Scripting (XSS) vulnerabilityxtendify · woffice · CWE-79 | Orta6,1 | — | %0,3 | 4 Tem 2024 |
24İzleyin | CVE-2024-37471İstismar yok | WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerabilityxtendify · woffice · CWE-79 | Orta6,1 | — | %0,3 | 4 Tem 2024 |
21İzleyin | CVE-2025-2797İstismar yok | Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approvalxtendify · woffice · CWE-352 | Orta5,4 | — | %0,1 | 4 Nis 2025 |
19İzleyin | CVE-2023-32738İstismar yok | WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)xtendify · eonet manual user approve · CWE-79 | Orta4,8 | — | %0,3 | 27 Eki 2023 |
- CVE-2024-4323439İzleyin
WordPress Woffice theme <= 5.4.14 - Unauthenticated Account Takeover vulnerability
KritikCVSS 9,8İstismar yokEPSS %1xtendify · woffice16 Ara 2024
- CVE-2025-279839İzleyin
Woffice <= 5.4.21 - Authentication Bypass via Registration Role
KritikCVSS 9,8İstismar yokEPSS %1xtendify · woffice4 Nis 2025
- CVE-2024-4315339İzleyin
WordPress Woffice theme <= 5.4.10 - Unauthenticated Privilege Escalation vulnerability
KritikCVSS 9,8İstismar yokEPSS %1xtendify · woffice13 Ağu 2024
- CVE-2024-3747039İzleyin
WordPress Woffice Core plugin <= 5.4.8 - Unauthenticated Broken Access Control vulnerability
KritikCVSS 9,8İstismar yokEPSS %1xtendify · woffice1 Kas 2024
- CVE-2025-278035İzleyin
Woffice Core <= 5.4.21 - Authenticated (Subscriber+) Arbitrary File Upload
YüksekCVSS 8,8İstismar yokEPSS %1xtendify · woffice4 Nis 2025
- CVE-2023-4618935İzleyin
WordPress Google Calendar Events Plugin <= 3.2.5 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0xtendify · simple calendar25 Eki 2023
- CVE-2025-769430İzleyin
Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletion
YüksekCVSS 7,5İstismar yokEPSS %1xtendify · woffice2 Ağu 2025
- CVE-2024-854924İzleyin
Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0xtendify · simple calendar24 Eyl 2024
- CVE-2024-3747224İzleyin
WordPress Woffice theme <= 5.4.8 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0xtendify · woffice4 Tem 2024
- CVE-2024-3747124İzleyin
WordPress Woffice Core plugin <= 5.4.8 - Site Wide Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0xtendify · woffice4 Tem 2024
- CVE-2025-279721İzleyin
Woffice Core <= 5.4.21 - Cross-Site Request Forgery to User Registration Approval
OrtaCVSS 5,4İstismar yokEPSS %0xtendify · woffice4 Nis 2025
- CVE-2023-3273819İzleyin
WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 4,8İstismar yokEPSS %0xtendify · eonet manual user approve27 Eki 2023