Vulnerabilidades en Unknown
5450 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2021-24164—Ninja Forms < 3.4.34.1 - Authenticated OAuth Connection Key DisclosureEPSS 0.9%CVE-2025-4302MEDIUMStop User Enumeration < 1.7.3 - Protection BypassEPSS 0.9%CVE-2021-24724—Timetable and Event Schedule by MotoPress < 2.3.19 - Author+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-25035—Backup and Staging by WP Time Capsule < 1.22.7 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25083—Registrations for the Events Calendar < 2.7.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25062—Orders Tracking for WooCommerce < 1.1.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-1029—Limit Login Attempts < 4.0.72 - Admin+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-25015—myCred < 2.4 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25031—Image Hover Effects Ultimate < 9.7.1 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2023-0602—Twittee Text Tweet <= 1.0.8 - Reflected XSSEPSS 0.9%CVE-2023-1207HIGHHTTP Headers < 1.18.8 - Admin+ SQL InjectionEPSS 0.9%CVE-2022-4157MEDIUMContest Gallery < 19.1.5 - Admin+ SQL InjectionEPSS 0.9%CVE-2023-5041HIGHTrack The Click < 0.3.12 - Author+ Time-Based Blind SQL InjectionEPSS 0.9%CVE-2022-4158HIGHContest Gallery < 19.1.5 - Unauthenticated SQL InjectionEPSS 0.9%CVE-2021-24720—GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%CVE-2023-0334MEDIUMShortPixel Adaptive Images < 3.6.3 - Reflected XSSEPSS 0.9%CVE-2021-25041—Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2022-3934MEDIUMFlat PM < 3.0.13 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-3933MEDIUMEssential Real Estate < 3.9.6 - Reflected Cross-Site-ScriptingEPSS 0.9%CVE-2023-5601CRITICALWooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File UploadEPSS 0.9%