Vulnerabilities in unknown
5,518 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2024-13569HIGHFront End Users <= 3.2.32 - Reflected XSSEPSS 0.5%CVE-2022-4005MEDIUMDonation Button <= 4.0.0 - Contributor+ Stored XSSEPSS 0.5%CVE-2021-24989—Accept Donations with PayPal < 1.3.4 - Arbitrary Post Deletion via CSRFEPSS 0.5%CVE-2022-3909MEDIUMAdd Comments <= 1.0.1 - Admin+ Stored XSSEPSS 0.5%CVE-2022-3537HIGHRole Based Pricing for WooCommerce < 1.6.2 - Subscriber+ Arbitrary File UploadEPSS 0.5%CVE-2022-4010MEDIUMImage Hover Effects < 5.5 - Admin+ Stored XSSEPSS 0.5%CVE-2022-0446—Simple Banner < 2.12.0 - Admin+ Stored Cross Site ScriptingEPSS 0.5%CVE-2022-2245—Counter Box < 1.2.1 - Arbitrary Counter Activation/Deactivation via CSRFEPSS 0.5%CVE-2021-25095—IP2Location Country Blocker < 2.26.5 - Subscriber+ Arbitrary Country BanEPSS 0.5%CVE-2021-24641—Images to WebP < 1.9 - Multiple Cross Site Request Forgery (CSRF)EPSS 0.5%CVE-2024-13055HIGHDyn Business Panel <= 1.0.0 - Reflected XSSEPSS 0.5%CVE-2022-1572—HTML2WP <= 1.0.0 - Subscriber+ Arbitrary File DeletionEPSS 0.5%CVE-2021-24636—Print My Blog < 3.4.2 - Plugin Deactivation via CSRFEPSS 0.5%CVE-2026-14334HIGHBooking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File UploadEPSS 0.5%CVE-2022-23179MEDIUMContact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2021-24914—Tawk.to Live Chat < 0.6.0 - Subscriber+ Visitor Monitoring & Chat RemovalEPSS 0.5%CVE-2026-16263HIGHWP Maps < 4.9.7 - Subscriber+ Local File InclusionEPSS 0.5%CVE-2023-1090MEDIUMWP SMTP Mailing Queue < 2.0.1 - Admin+ Stored XSSEPSS 0.5%CVE-2023-7239HIGHwp-dashboard-notes < 1.0.11 - Contributor+ Arbitrary Private Notes Update via IDOREPSS 0.5%CVE-2021-24922—Pixel Cat Lite < 2.6.2 - CSRF to Stored Cross-Site ScriptingEPSS 0.5%