Rtcamp
Rtcamp Rtmedia: vulnerabilidades y CVE
Rtcamp Rtmedia tiene 12 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses8
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88912 | Media (4.2) | 0.19% | — | 13 sept 2026 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with… |
| CVE-2026-16482 | Alta (7.5) | 0.34% | — | 12 sept 2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient… |
| CVE-2026-66592 | Crítica (9.3) | 0.40% | — | 20 ago 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. |
| CVE-2026-59551 | Alta (8.5) | 0.36% | — | 27 jul 2026 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. |
| CVE-2026-59549 | Crítica (9.3) | 0.40% | — | 27 jul 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. |
| CVE-2026-15287 | Media (6.5) | 0.38% | — | 10 jul 2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on… |
| CVE-2026-40773 | Media (6.5) | 0.30% | — | 15 jun 2026 | Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. |
| CVE-2025-9218 | Baja (3.7) | 0.32% | — | 13 dic 2025 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active,… |
| CVE-2023-41951 | Media (4.3) | 0.56% | — | 13 dic 2024 | Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress… |
| CVE-2024-3293 | Alta (8.8) | 1.4% | — | 23 abr 2024 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on… |
| CVE-2023-5939 | Alta (7.2) | 1.3% | — | 26 dic 2023 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users. |
| CVE-2023-5931 | Alta (8.8) | 0.82% | — | 26 dic 2023 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary… |