Vulnerabilities in unknown
5,484 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-0420—RegistrationMagic < 5.0.2.2 - Admin+ SQL InjectionEPSS 1.5%CVE-2022-1006—Advanced Booking Calendar < 1.7.1 - Admin+ SQLiEPSS 1.5%CVE-2023-0487HIGHMy Sticky Elements < 2.0.9 - Admin+ SQLiEPSS 1.5%CVE-2021-24894—Reviews Plus < 1.2.14 - Subscriber+ Reviews DoSEPSS 1.5%CVE-2021-24354—Simple 301 Redirects by BetterLinks - 2.0.0-2.0.3 - Arbitrary Plugin InstallationEPSS 1.5%CVE-2022-1904—Easy Pricing Tables < 3.2.1 - Reflected Cross-Site-ScriptingEPSS 1.5%CVE-2022-1273—Import WP < 2.4.6 - Admin+ Arbitrary File Upload to RCEEPSS 1.5%CVE-2022-0383—WP Review Slider < 11.0 - Admin+ SQL InjectionEPSS 1.5%CVE-2022-23911—AP Custom Testimonial < 1.4.8 - Admin+ SQL InjectionEPSS 1.5%CVE-2026-13147CRITICALKirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apisEPSS 1.5%CVE-2022-0687—Amelia < 1.0.46 - Manager+ RCEEPSS 1.5%CVE-2022-4057MEDIUMAutoptimize < 3.1.0 - Sensitive Data DisclosureEPSS 1.5%CVE-2022-2187—Contact Form 7 Captcha < 0.1.2 - Reflected Cross-Site ScriptingEPSS 1.5%CVE-2022-0206—NewStatPress < 1.3.6 - Reflected Cross-Site ScriptingEPSS 1.5%CVE-2022-3394HIGHWP All Export Pro < 1.7.9 - Authenticated Code InjectionEPSS 1.5%CVE-2021-24125—Contact Form Submissions < 1.7.1 - Authenticated SQL InjectionEPSS 1.5%CVE-2022-0920—Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data DisclosureEPSS 1.5%CVE-2023-3186—Supsystic Popup < 1.10.19 - Prototype PollutionEPSS 1.5%CVE-2022-1412—Log WP_Mail <= 0.1 - Email Logs Publicly AccessibleEPSS 1.5%CVE-2021-25119—AGIL <= 1.0 - Admin+ Arbitrary File UploadEPSS 1.4%