YITHEMES kayıtları
yithemes üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %47,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-862 Missing Authorization2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-285 Improper Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2021-3120İstismar yok | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers yithemes · yith woocommerce gift cards · CWE-434 | Kritik9,8 | — | %36,8 | 22 Şub 2021 |
43Planlayın | CVE-2022-45359İstismar yok | WordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File Uploadyithemes · yith woocommerce gift cards · CWE-434 | Kritik9,8 | — | %13,5 | 6 Ara 2022 |
37İzleyin | CVE-2024-47350İstismar yok | WordPress YITH WooCommerce Ajax Search plugin <= 2.8.0 - SQL Injection vulnerabilityyithemes · yith woocommerce ajax search · CWE-89 | Kritik9,3 | — | %0,4 | 6 Eki 2024 |
35İzleyin | CVE-2023-49777İstismar yok | WordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object Injectionyithemes · yith woocommerce product add-ons · CWE-502 | Yüksek8,8 | — | %0,7 | 31 Ara 2023 |
35İzleyin | CVE-2024-30470İstismar yok | WordPress YITH WooCommerce Account Funds Premium plugin <= 1.32.0 - Broken Access Control vulnerabilityyithemes · woocommerce account funds · CWE-862 | Yüksek8,8 | — | %0,4 | 9 Haz 2024 |
26İzleyin | CVE-2015-9429İstismar yok | The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-moyithemes · yith maintenance mode · CWE-352 | Orta6,5 | — | %0,9 | 25 Eyl 2019 |
24İzleyin | CVE-2024-4455Kavram kanıtı | YITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site Scriptingyithemes · yith woocommerce ajax search · CWE-79 | Orta6,1 | — | %1,0 | 24 May 2024 |
24İzleyin | CVE-2022-0818İstismar yok | Coupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSSyithemes · woocommerce affiliate · CWE-79 | Orta6,1 | — | %0,9 | 28 Mar 2022 |
24İzleyin | CVE-2024-8665İstismar yok | YITH Custom Login <= 1.7.3 - Reflected Cross-Site Scriptingyithemes · yith custom login · CWE-79 | Orta6,1 | — | %0,5 | 13 Eyl 2024 |
24İzleyin | CVE-2024-50448İstismar yok | WordPress YITH WooCommerce Product Add-Ons plugin <= 4.14.1 - Reflected Cross Site Scripting (XSS) vulnerabilityyithemes · yith woocommerce product add-ons · CWE-79 | Orta6,1 | — | %0,3 | 28 Eki 2024 |
21İzleyin | CVE-2021-36841İstismar yok | YITH Maintenance Mode (WordPress plugin) <= 1.3.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability.yithemes · yith maintenance mode · CWE-79 | Orta5,4 | — | %0,6 | 27 Eyl 2021 |
21İzleyin | CVE-2024-0870İstismar yok | YITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings Updateyithemes · yith woocommerce gift cards · CWE-285 | Orta5,3 | — | %0,5 | 14 May 2024 |
21İzleyin | CVE-2024-7846İstismar yok | YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSSyithemes · yith woocommerce ajax search · CWE-79 | Orta5,4 | — | %0,3 | 23 Eyl 2024 |
21İzleyin | CVE-2024-35680İstismar yok | WordPress YITH WooCommerce Product Add-Ons plugin <= 4.9.2 - Content Injection vulnerabilityyithemes · yith woocommerce product add-ons · CWE-80 | Orta5,3 | — | %0,3 | 10 Haz 2024 |
19İzleyin | CVE-2021-36845İstismar yok | YITH Maintenance Mode (WordPress plugin) <= 1.3.8 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesyithemes · yith maintenance mode · CWE-79 | Orta4,8 | — | %0,7 | 27 Eyl 2021 |
19İzleyin | CVE-2024-35732İstismar yok | WordPress YITH Custom Login plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerabilityyithemes · yith custom login · CWE-79 | Orta4,8 | — | %0,3 | 8 Haz 2024 |
19İzleyin | CVE-2024-35698İstismar yok | WordPress YITH WooCommerce Tab Manager plugin <= 1.35.0 - Cross Site Scripting (XSS) vulnerabilityyithemes · yith woocommerce tab manager · CWE-79 | Orta4,8 | — | %0,3 | 8 Haz 2024 |
17İzleyin | CVE-2019-16251İstismar yok | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.yithemes · yith woocommerce wishlist | Orta4,3 | — | %0,9 | 31 Eki 2019 |
17İzleyin | CVE-2024-6799İstismar yok | YITH Essential Kit for WooCommerce #1 <= 2.34.0 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivationyithemes · yith essential kit for woocommerce · CWE-862 | Orta4,3 | — | %0,3 | 19 Tem 2024 |
- CVE-2021-312050Planlayın
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers
KritikCVSS 9,8İstismar yokEPSS %37yithemes · yith woocommerce gift cards22 Şub 2021
- CVE-2022-4535943Planlayın
WordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File Upload
KritikCVSS 9,8İstismar yokEPSS %14yithemes · yith woocommerce gift cards6 Ara 2022
- CVE-2024-4735037İzleyin
WordPress YITH WooCommerce Ajax Search plugin <= 2.8.0 - SQL Injection vulnerability
KritikCVSS 9,3İstismar yokEPSS %0yithemes · yith woocommerce ajax search6 Eki 2024
- CVE-2023-4977735İzleyin
WordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object Injection
YüksekCVSS 8,8İstismar yokEPSS %1yithemes · yith woocommerce product add-ons31 Ara 2023
- CVE-2024-3047035İzleyin
WordPress YITH WooCommerce Account Funds Premium plugin <= 1.32.0 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0yithemes · woocommerce account funds9 Haz 2024
- CVE-2015-942926İzleyin
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mo
OrtaCVSS 6,5İstismar yokEPSS %1yithemes · yith maintenance mode25 Eyl 2019
- CVE-2024-445524İzleyin
YITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting
OrtaCVSS 6,1Kavram kanıtıEPSS %1yithemes · yith woocommerce ajax search24 May 2024
- CVE-2022-081824İzleyin
Coupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %1yithemes · woocommerce affiliate28 Mar 2022
- CVE-2024-866524İzleyin
YITH Custom Login <= 1.7.3 - Reflected Cross-Site Scripting
OrtaCVSS 6,1İstismar yokEPSS %0yithemes · yith custom login13 Eyl 2024
- CVE-2024-5044824İzleyin
WordPress YITH WooCommerce Product Add-Ons plugin <= 4.14.1 - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0yithemes · yith woocommerce product add-ons28 Eki 2024
- CVE-2021-3684121İzleyin
YITH Maintenance Mode (WordPress plugin) <= 1.3.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability.
OrtaCVSS 5,4İstismar yokEPSS %1yithemes · yith maintenance mode27 Eyl 2021
- CVE-2024-087021İzleyin
YITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings Update
OrtaCVSS 5,3İstismar yokEPSS %1yithemes · yith woocommerce gift cards14 May 2024
- CVE-2024-784621İzleyin
YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %0yithemes · yith woocommerce ajax search23 Eyl 2024
- CVE-2024-3568021İzleyin
WordPress YITH WooCommerce Product Add-Ons plugin <= 4.9.2 - Content Injection vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0yithemes · yith woocommerce product add-ons10 Haz 2024
- CVE-2021-3684519İzleyin
YITH Maintenance Mode (WordPress plugin) <= 1.3.8 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
OrtaCVSS 4,8İstismar yokEPSS %1yithemes · yith maintenance mode27 Eyl 2021
- CVE-2024-3573219İzleyin
WordPress YITH Custom Login plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 4,8İstismar yokEPSS %0yithemes · yith custom login8 Haz 2024
- CVE-2024-3569819İzleyin
WordPress YITH WooCommerce Tab Manager plugin <= 1.35.0 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 4,8İstismar yokEPSS %0yithemes · yith woocommerce tab manager8 Haz 2024
- CVE-2019-1625117İzleyin
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
OrtaCVSS 4,3İstismar yokEPSS %1yithemes · yith woocommerce wishlist31 Eki 2019
- CVE-2024-679917İzleyin
YITH Essential Kit for WooCommerce #1 <= 2.34.0 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation
OrtaCVSS 4,3İstismar yokEPSS %0yithemes · yith essential kit for woocommerce19 Tem 2024