Atlasgondal
Atlasgondal Export ALL Urls: vulnerabilidades y CVE
Atlasgondal Export ALL Urls tiene 8 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2696 | Media (5.3) | 0.34% | — | 1 abr 2026 | The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) in a predictable pattern using a random 6-digit number. These files are stored in the publicly… |
| CVE-2023-51510 | Alta (8.8) | 0.23% | — | 16 mar 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Atlas Gondal Export Media URLs.This issue affects Export Media URLs: from n/a through 1.0. |
| CVE-2023-3118 | Media (6.1) | 0.56% | — | 10 jul 2023 | The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege… |
| CVE-2022-27856 | Media (5.4) | 0.38% | — | 10 may 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions. |
| CVE-2022-2638 | Media (6.5) | 1.2% | — | 29 ago 2022 | The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file… |
| CVE-2022-29452 | Media (4.8) | 0.51% | — | 15 jun 2022 | Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress. |
| CVE-2022-0914 | Media (6.5) | 0.65% | — | 11 abr 2022 | The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an… |
| CVE-2022-0892 | Media (6.1) | 0.80% | — | 11 abr 2022 | The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting |