İçeriğe atla
Noroxi

YITHEMES kayıtları

yithemes üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%47,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2021-3120
    50Planlayın

    An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers

    KritikCVSS 9,8İstismar yokEPSS %37

    yithemes · yith woocommerce gift cards22 Şub 2021

  • CVE-2022-45359
    43Planlayın

    WordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File Upload

    KritikCVSS 9,8İstismar yokEPSS %14

    yithemes · yith woocommerce gift cards6 Ara 2022

  • CVE-2024-47350
    37İzleyin

    WordPress YITH WooCommerce Ajax Search plugin <= 2.8.0 - SQL Injection vulnerability

    KritikCVSS 9,3İstismar yokEPSS %0

    yithemes · yith woocommerce ajax search6 Eki 2024

  • CVE-2023-49777
    35İzleyin

    WordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object Injection

    YüksekCVSS 8,8İstismar yokEPSS %1

    yithemes · yith woocommerce product add-ons31 Ara 2023

  • CVE-2024-30470
    35İzleyin

    WordPress YITH WooCommerce Account Funds Premium plugin <= 1.32.0 - Broken Access Control vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    yithemes · woocommerce account funds9 Haz 2024

  • CVE-2015-9429
    26İzleyin

    The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mo

    OrtaCVSS 6,5İstismar yokEPSS %1

    yithemes · yith maintenance mode25 Eyl 2019

  • CVE-2024-4455
    24İzleyin

    YITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    yithemes · yith woocommerce ajax search24 May 2024

  • CVE-2022-0818
    24İzleyin

    Coupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSS

    OrtaCVSS 6,1İstismar yokEPSS %1

    yithemes · woocommerce affiliate28 Mar 2022

  • CVE-2024-8665
    24İzleyin

    YITH Custom Login <= 1.7.3 - Reflected Cross-Site Scripting

    OrtaCVSS 6,1İstismar yokEPSS %0

    yithemes · yith custom login13 Eyl 2024

  • CVE-2024-50448
    24İzleyin

    WordPress YITH WooCommerce Product Add-Ons plugin <= 4.14.1 - Reflected Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %0

    yithemes · yith woocommerce product add-ons28 Eki 2024

  • CVE-2021-36841
    21İzleyin

    YITH Maintenance Mode (WordPress plugin) <= 1.3.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability.

    OrtaCVSS 5,4İstismar yokEPSS %1

    yithemes · yith maintenance mode27 Eyl 2021

  • CVE-2024-0870
    21İzleyin

    YITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings Update

    OrtaCVSS 5,3İstismar yokEPSS %1

    yithemes · yith woocommerce gift cards14 May 2024

  • CVE-2024-7846
    21İzleyin

    YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS

    OrtaCVSS 5,4İstismar yokEPSS %0

    yithemes · yith woocommerce ajax search23 Eyl 2024

  • CVE-2024-35680
    21İzleyin

    WordPress YITH WooCommerce Product Add-Ons plugin <= 4.9.2 - Content Injection vulnerability

    OrtaCVSS 5,3İstismar yokEPSS %0

    yithemes · yith woocommerce product add-ons10 Haz 2024

  • CVE-2021-36845
    19İzleyin

    YITH Maintenance Mode (WordPress plugin) <= 1.3.8 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities

    OrtaCVSS 4,8İstismar yokEPSS %1

    yithemes · yith maintenance mode27 Eyl 2021

  • CVE-2024-35732
    19İzleyin

    WordPress YITH Custom Login plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 4,8İstismar yokEPSS %0

    yithemes · yith custom login8 Haz 2024

  • CVE-2024-35698
    19İzleyin

    WordPress YITH WooCommerce Tab Manager plugin <= 1.35.0 - Cross Site Scripting (XSS) vulnerability

    OrtaCVSS 4,8İstismar yokEPSS %0

    yithemes · yith woocommerce tab manager8 Haz 2024

  • CVE-2019-16251
    17İzleyin

    plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

    OrtaCVSS 4,3İstismar yokEPSS %1

    yithemes · yith woocommerce wishlist31 Eki 2019

  • CVE-2024-6799
    17İzleyin

    YITH Essential Kit for WooCommerce #1 <= 2.34.0 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation

    OrtaCVSS 4,3İstismar yokEPSS %0

    yithemes · yith essential kit for woocommerce19 Tem 2024