Vulnerabilidades em unknown
4.771 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2021-24928—Rearrange Woocommerce Products < 3.0.8 - Subscriber+ SQL InjectionEPSS 0.9%CVE-2021-24724—Timetable and Event Schedule by MotoPress < 2.3.19 - Author+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-25035—Backup and Staging by WP Time Capsule < 1.22.7 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25062—Orders Tracking for WooCommerce < 1.1.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25015—myCred < 2.4 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25031—Image Hover Effects Ultimate < 9.7.1 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25083—Registrations for the Events Calendar < 2.7.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2023-0602—Twittee Text Tweet <= 1.0.8 - Reflected XSSEPSS 0.9%CVE-2023-1207HIGHHTTP Headers < 1.18.8 - Admin+ SQL InjectionEPSS 0.9%CVE-2015-20019—Content text slider on post < 6.9 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%CVE-2021-25041—Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2017-20008—myCRED < 1.7.8 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-4157MEDIUMContest Gallery < 19.1.5 - Admin+ SQL InjectionEPSS 0.9%CVE-2022-4158HIGHContest Gallery < 19.1.5 - Unauthenticated SQL InjectionEPSS 0.9%CVE-2021-24720—GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%CVE-2023-5041HIGHTrack The Click < 0.3.12 - Author+ Time-Based Blind SQL InjectionEPSS 0.9%CVE-2023-0334MEDIUMShortPixel Adaptive Images < 3.6.3 - Reflected XSSEPSS 0.9%CVE-2022-3907HIGHClerk < 4.0.0 - Authentication Bypass and API Keys DisclosureEPSS 0.9%CVE-2022-2370—YaySMTP < 2.2.1 - Subscriber+ SMTP Credentials LeakEPSS 0.9%CVE-2023-5601CRITICALWooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File UploadEPSS 0.9%