Vulnerabilidades em unknown
4.771 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-2593—Better Search and Replace < 1.4.1 - Admin+ SQLiEPSS 1.1%CVE-2021-24135—WP Customer Reviews < 3.4.3 - Multiple Unauthenticated and Low Priv Authenticated Stored XSSEPSS 1.1%CVE-2023-1124HIGHShopping Cart & eCommerce Store < 5.4.3 - Admin+ LFIEPSS 1.1%CVE-2022-1123—Leaflet Maps Marker < 3.12.5 - Admin+ SQLiEPSS 1.1%CVE-2023-1196HIGHAdvanced Custom Fields - Contributor+ PHP Object InjectionEPSS 1.1%CVE-2022-2599—Anti-Malware Security and Brute-Force Firewall < 4.21.83 - Reflected Cross-Site ScriptingEPSS 1.1%CVE-2023-2493—All In One Redirection < 2.2.0 - Admin+ SQLiEPSS 1.1%CVE-2022-4237HIGHWelcart e-Commerce < 2.8.6 - Subscriber+ PHAR DeserialisationEPSS 1.1%CVE-2022-2089—Bold Page Builder < 4.3.3 - Admin+ Stored Cross-Site ScriptingEPSS 1.1%CVE-2022-3603CRITICALExport customers list CSV for WooCommerce < 2.0.69 - CSV InjectionEPSS 1.1%CVE-2023-1890MEDIUMTablesome < 1.0.9 - Reflected XSSEPSS 1.1%CVE-2021-24154—Theme Editor < 2.6 - Authenticated Arbitrary File DownloadEPSS 1.1%CVE-2022-2460MEDIUMWPDating < 7.4.0 - Multiple Unauthenticated SQLiEPSS 1.1%CVE-2023-6222HIGHQuttera Web Malware Scanner < 3.4.2.1 - Admin+ Path TraversalEPSS 1.1%CVE-2022-3246HIGHBlog2Social < 6.9.10 - Subscriber+ SQLiEPSS 1.1%CVE-2022-3915CRITICALDokan < 3.7.6 - Unauthenticated SQLiEPSS 1.1%CVE-2022-3865HIGHWP User Merger < 1.5.3 - Admin+ SQLi via IDEPSS 1.1%CVE-2022-3849HIGHWP User Merger < 1.5.3 - Admin+ SQLi via user_idEPSS 1.1%CVE-2022-2958—BadgeOS < 3.7.1.3 - Subscriber+ SQLiEPSS 1.1%CVE-2022-3769HIGHOWM Weather < 5.6.9 - Contributor+ SQLiEPSS 1.1%