Vulnerabilidades en unknown
4771 resultadosAnálisis Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2021-24566HIGHWooCommerce Currency Switcher < 1.3.7 - Authenticated (Low Privilege) Local File InclusionEPSS 1.3%CVE-2021-24973—Site Reviews < 5.17.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.3%CVE-2022-4489HIGHWOOF - Products Filter for WooCommerce < 1.3.2 - Admin+ PHP Object InjectionEPSS 1.3%CVE-2022-1037—EXMAGE < 1.0.7 - Admin+ Blind SSRFEPSS 1.3%CVE-2021-24441—Sign-up Sheets < 1.0.14 - Authenticated CSV InjectionEPSS 1.3%CVE-2021-25064—Wow Countdowns <= 3.1.2 - Admin+ SQLiEPSS 1.3%CVE-2021-24350—Visitors <= 0.3 - Unauthenticated Stored Cross-Site Scripting (XSS)EPSS 1.3%CVE-2021-24777—Hotscot Contact Form < 1.3 - Admin+ SQL InjectionEPSS 1.3%CVE-2023-0381HIGHGigPress <= 2.3.28 - Subscriber+ SQLiEPSS 1.3%CVE-2021-25086—Advanced Page Visit Counter < 6.1.2 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.3%CVE-2021-24662—Game Server Status <= 1.0 - Admin+ SQL InjectionEPSS 1.3%CVE-2022-1800—Export any WordPress data to XML/CSV < 1.3.5 - Admin+ SQL InjectionEPSS 1.3%CVE-2023-4238HIGHPrevent files / folders access < 2.5.2 - Admin+ Arbitrary File UploadEPSS 1.3%CVE-2021-24717—AutomatorWP < 1.7.6 - Missing Authorization and Privilege EscalationEPSS 1.3%CVE-2022-0190—Ad Invalid Click Protector (AICP) < 1.2.6 - Authenticated SQL InjectionEPSS 1.3%CVE-2022-3393CRITICALPost to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionEPSS 1.3%CVE-2022-1583—External Links in New Window / New Tab < 1.43 - TabnabbingEPSS 1.3%CVE-2021-24835—WCFM - Frontend Manager for WooCommerce < 6.5.12 - Customer/Subscriber+ SQL InjectionEPSS 1.3%CVE-2021-24669—MAZ Loader < 1.3.3 - Contributor+ SQL InjectionEPSS 1.3%CVE-2021-24758—Email Log < 2.4.7 - Admin+ SQL InjectionEPSS 1.3%