« Volver al listado

Dash10

Dash10 Oauth Server: vulnerabilidades y CVE

Dash10 Oauth Server tiene 4 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses1
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97288Media (6.5)0.22%—30 sept 2026
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
CVE-2022-4148Media (4.3)0.26%—20 mar 2023
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete…
CVE-2022-3894Media (4.3)0.25%—20 mar 2023
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow…
CVE-2015-9435Crítica (9.8)2.1%—26 sept 2019
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript1
  2. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.