Vulnerabilidades em saadiqbal
49 resultadosAnálise Vexday
Saadiqbal apresenta 46 vulnerabilidades catalogadas, com apenas 2 classificadas como críticas e nenhuma sob exploração ativa confirmada. A fraqueza dominante é CWE-862 (Autorização Ausente), indicando falhas no controle de acesso, enquanto o ritmo de descoberta permanece moderado com 5 vulnerabilidades nos últimos 90 dias.
CVE-2023-6875CRITICALPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app APIEPSS 90.3%CVE-2025-11833CRITICALPost SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log DisclosureEPSS 51.0%CVE-2019-25150HIGHEmail Templates <= 1.3 - HTML InjectionEPSS 1.2%CVE-2024-8126HIGHAdvanced File Manager <= 5.2.8 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2023-7027HIGHPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Unauthenticated Stored Cross-Site Scripting via deviceEPSS 0.9%CVE-2024-13333HIGHAdvanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2024-8704HIGHAdvanced File Manager <= 5.2.8 - Authenticated (Administrator+) Local JavaScript File Inclusion via fma_localeEPSS 0.9%CVE-2024-11201MEDIUMmyCred – Loyalty Points and Rewards plugin <= 2.7.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send ShortcodeEPSS 0.8%CVE-2025-0818MEDIUMMultiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File DeletionEPSS 0.7%CVE-2024-11391HIGHAdvanced File Manager <= 5.2.10 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.7%CVE-2026-6627HIGHWPFormify <= 1.1.1 - Missing AuthorizationEPSS 0.6%CVE-2024-5598HIGHAdvanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory ListingEPSS 0.6%CVE-2021-4422MEDIUMPOST SMTP Mailer <= 2.0.20 - Cross-Site Request Forgery BypassEPSS 0.5%CVE-2023-3082HIGHPost SMTP <= 2.5.7 - Unauthenticated Stored Cross-Site Scripting via EmailEPSS 0.5%CVE-2024-5207HIGHPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL InjectionEPSS 0.5%CVE-2023-6629MEDIUMPOST SMTP Mailer <= 2.8.6 - Reflected Cross-Site Scripting via msgEPSS 0.4%CVE-2022-4974MEDIUMFreemius SDK <= 2.4.2 - Missing Authorization ChecksEPSS 0.4%CVE-2024-13713MEDIUMWPExperts Square For GiveWP <= 1.3.1 - Authenticated (Subscriber+) SQL InjectionEPSS 0.4%CVE-2024-5861MEDIUMWP Easy Pay (Free) <= 4.2.3 - Missing Authorization to Unauthenticated Service DisconnectionEPSS 0.4%CVE-2021-4411MEDIUMWP EasyPay – Square for WordPress <= 3.2.0 - Cross-Site Request Forgery BypassEPSS 0.4%