salephpscripts 漏洞与 CVE 列表(4)

产品(CPE): — CVE 数: 4

salephpscripts 漏洞概览

汇总 salephpscripts 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

常见弱点模式包括 SQL 注入与跨站脚本,在 软件部署与生产负载 使用场景中可能带来 数据泄露与会话劫持 等风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 144 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2024-3673 The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues. [email protected] 9.1 92.16% 2024-08-30 2025-05-16
CVE-2024-3669 The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin [email protected] 6.8 0.65% 2024-07-30 2025-05-28
CVE-2024-3552 The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based. [email protected] 9.8 93.35% 2024-06-13 2025-03-25
CVE-2023-2201 The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. [email protected] 8.8 0.38% 2023-06-02 2026-04-08
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence