本ページは wpsupportplus wp_support_plus_responsive_ticket_system に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2019-15331 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. | [email protected] | 6.1 | 0.91% | 2019-08-22 | 2024-11-21 |
| CVE-2016-10930 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | [email protected] | 9.8 | 2.02% | 2019-08-22 | 2024-11-21 |
| CVE-2014-10391 | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | [email protected] | 6.1 | 0.91% | 2019-08-22 | 2024-11-21 |
| CVE-2014-10390 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | [email protected] | 9.1 | 2.50% | 2019-08-22 | 2024-11-21 |
| CVE-2014-10389 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. | [email protected] | 9.8 | 2.22% | 2019-08-22 | 2024-11-21 |
| CVE-2014-10388 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. | [email protected] | 5.3 | 1.33% | 2019-08-22 | 2024-11-21 |
| CVE-2014-10387 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. | [email protected] | 9.8 | 1.80% | 2019-08-22 | 2024-11-21 |
| CVE-2019-7299 | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php. | [email protected] | 6.1 | 1.66% | 2019-03-21 | 2024-11-21 |
| CVE-2018-1000131 | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later. | [email protected] | 9.8 | 2.12% | 2018-03-14 | 2024-11-21 |