Vulnerabilidades em unknown
4.771 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-3243HIGHImport all XML, CSV & TXT into WordPress < 6.5.8 - Admin+ SQLiEPSS 1.0%CVE-2023-1780—Companion Sitemap Generator < 4.5.3 - Reflected XSSEPSS 1.0%CVE-2021-24366MEDIUMAdmin Columns Free < 4.3 & Pro < 5.5.1 - Admin+ Stored XSS in LabelEPSS 1.0%CVE-2022-4357CRITICALLetsRecover < 1.2.0 - Unauthenticated SQLiEPSS 1.0%CVE-2021-24845—Improved Include Page <= 1.2 - Contributor+ Arbitrary Posts/Pages AccessEPSS 1.0%CVE-2021-24872—Get Custom Field Values < 4.0 - Contributors+ Arbitrary Post Metadata AccessEPSS 1.0%CVE-2022-1558—Curtain <= 1.0.2 - Admin+ Stored Cross-Site ScriptingEPSS 1.0%CVE-2022-1396—Donorbox < 7.1.7 - Admin+ Stored Cross-Site ScriptingEPSS 1.0%CVE-2022-1559—Clipr <= 1.2.3 - Admin+ Stored Cross-Site ScriptingEPSS 1.0%CVE-2025-5397CRITICALJobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication BypassEPSS 1.0%CVE-2022-3858HIGHChaty < 3.0.3 - Admin+ SQLiEPSS 1.0%CVE-2022-2362—Download Manager < 3.2.50 - Bypass IP Address Blocking RestrictionEPSS 1.0%CVE-2022-3558HIGHImport and export users and customers < 1.20.5 - Subscriber+ CSV InjectionEPSS 1.0%CVE-2022-0163—Smart Forms < 2.6.71 - Subscriber+ Form Data DownloadEPSS 1.0%CVE-2022-2559—Fluent Support < 1.5.8 - Admin+ SQLiEPSS 1.0%CVE-2023-4311—Vrm 360 3D Model Viewer <= 1.2.1 - Contributor+ Arbitrary File Upload Leading to RCEEPSS 1.0%CVE-2023-3133—Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST APIEPSS 1.0%CVE-2022-4371HIGHWeb Invoice <= 2.1.3 - Authenticated SQLiEPSS 1.0%CVE-2022-4372HIGHWeb Invoice <= 2.1.3 - Authenticated SQLiEPSS 1.0%CVE-2022-4358HIGHWP RSS By Publishers <= 0.1 - Admin+ SQLiEPSS 1.0%