« Volver al listado

Cridio

Cridio Listingpro: vulnerabilidades y CVE

Cridio Listingpro tiene 23 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses10
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-65478Media (5.4)0.23%—23 jul 2026
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
CVE-2026-56046Media (6.5)0.22%—26 jun 2026
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
CVE-2026-39438Crítica (9.3)0.40%—17 jun 2026
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.
CVE-2026-28122Alta (7.1)0.25%—5 mar 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: from n/a through <=…
CVE-2025-64378Alta (7.1)0.20%—18 dic 2025
Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through < 2.9.10.
CVE-2025-64377Alta (8.1)0.40%—18 dic 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro:…
CVE-2025-64376Alta (7.1)0.18%—18 dic 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro allows Reflected XSS.This issue affects ListingPro: from n/a through < 2.9.10.
CVE-2025-63039Media (6.5)0.25%—18 dic 2025
Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9.
CVE-2025-63047Media (5.3)0.25%—9 dic 2025
Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9.
CVE-2025-63046Media (6.5)0.26%—9 dic 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows DOM-Based XSS.This issue affects ListingPro: from n/a through <=…
CVE-2025-60103Media (5.4)0.27%—26 sept 2025
Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.8.
CVE-2024-39623Alta (8.8)0.28%—2 ene 2025
Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4.
CVE-2024-39622Crítica (9.8)0.46%—29 ago 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4.
CVE-2024-39620Alta (8.8)0.44%—29 ago 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affects ListingPro: from n/a through <=…
CVE-2024-38795Crítica (9.8)0.46%—29 ago 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affects ListingPro: from n/a through <=…
CVE-2024-39624Alta (8.8)0.53%—1 ago 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.
CVE-2024-39621Alta (7.2)0.52%—1 ago 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through…
CVE-2024-39619Crítica (9.8)0.55%—1 ago 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through…
CVE-2020-36723Media (5.3)1.6%—7 jun 2023
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for…
CVE-2020-36719Crítica (9.8)4.3%—7 jun 2023
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the…
CVE-2019-19542Media (5.4)0.72%—26 dic 2019
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.
CVE-2019-19541Media (5.4)0.72%—26 dic 2019
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.
CVE-2019-19540Media (6.1)0.93%—26 dic 2019
The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.

Otros productos de Cridio