Codesolz
Codesolz Better Find AND Replace: vulnerabilidades y CVE
Codesolz Better Find AND Replace tiene 8 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3369 | Media (5.4) | 0.24% | — | 16 abr 2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input… |
| CVE-2025-9334 | Alta (8.8) | 0.50% | — | 8 nov 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction… |
| CVE-2025-12360 | Media (4.3) | 0.22% | — | 6 nov 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including,… |
| CVE-2025-53466 | Media (5.9) | 0.30% | — | 22 sept 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Stored XSS.This issue affects Better Find and… |
| CVE-2025-24734 | Alta (8.8) | 0.53% | — | 27 ene 2025 | Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affects Better Find and Replace: from n/a through <= 1.6.7. |
| CVE-2024-39636 | Alta (8.3) | 0.40% | — | 1 ago 2024 | Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1. |
| CVE-2022-1472 | Alta (7.2) | 1.3% | — | 20 jun 2022 | The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection |
| CVE-2021-24676 | Media (6.1) | 0.83% | — | 4 oct 2021 | The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue |