Bologer
Bologer Anycomment: vulnerabilidades y CVE
Bologer Anycomment tiene 7 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-62874 | Media (4.3) | 0.29% | — | 31 dic 2025 | Missing Authorization vulnerability in Alexander AnyComment anycomment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyComment: from n/a through <= 0.3.6. |
| CVE-2025-60240 | Alta (7.5) | 0.43% | — | 6 nov 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomment allows PHP Local File Inclusion.This issue affects AnyComment:… |
| CVE-2025-48091 | Alta (8.5) | 0.42% | — | 22 oct 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injection.This issue affects AnyComment: from n/a through <= 0.3.6. |
| CVE-2022-0279 | Baja (3.1) | 0.49% | — | 21 feb 2022 | The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other… |
| CVE-2022-0134 | Alta (8.8) | 0.65% | — | 21 feb 2022 | The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack |
| CVE-2021-24838 | Media (6.1) | 2.2% | — | 17 ene 2022 | The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which… |
| CVE-2018-21001 | Media (6.1) | 0.91% | — | 27 ago 2019 | The anycomment plugin before 0.0.33 for WordPress has XSS. |