Cridio
Cridio Listingpro: vulnerabilidades y CVE
Cridio Listingpro tiene 23 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses10
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65478 | Media (5.4) | 0.23% | — | 23 jul 2026 | Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. |
| CVE-2026-56046 | Media (6.5) | 0.22% | — | 26 jun 2026 | Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions. |
| CVE-2026-39438 | Crítica (9.3) | 0.40% | — | 17 jun 2026 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. |
| CVE-2026-28122 | Alta (7.1) | 0.25% | — | 5 mar 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: from n/a through <=… |
| CVE-2025-64378 | Alta (7.1) | 0.20% | — | 18 dic 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through < 2.9.10. |
| CVE-2025-64377 | Alta (8.1) | 0.40% | — | 18 dic 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro:… |
| CVE-2025-64376 | Alta (7.1) | 0.18% | — | 18 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro allows Reflected XSS.This issue affects ListingPro: from n/a through < 2.9.10. |
| CVE-2025-63039 | Media (6.5) | 0.25% | — | 18 dic 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9. |
| CVE-2025-63047 | Media (5.3) | 0.25% | — | 9 dic 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.9. |
| CVE-2025-63046 | Media (6.5) | 0.26% | — | 9 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows DOM-Based XSS.This issue affects ListingPro: from n/a through <=… |
| CVE-2025-60103 | Media (5.4) | 0.27% | — | 26 sept 2025 | Missing Authorization vulnerability in CridioStudio ListingPro listingpro-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ListingPro: from n/a through <= 2.9.8. |
| CVE-2024-39623 | Alta (8.8) | 0.28% | — | 2 ene 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4. |
| CVE-2024-39622 | Crítica (9.8) | 0.46% | — | 29 ago 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4. |
| CVE-2024-39620 | Alta (8.8) | 0.44% | — | 29 ago 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affects ListingPro: from n/a through <=… |
| CVE-2024-38795 | Crítica (9.8) | 0.46% | — | 29 ago 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affects ListingPro: from n/a through <=… |
| CVE-2024-39624 | Alta (8.8) | 0.53% | — | 1 ago 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4. |
| CVE-2024-39621 | Alta (7.2) | 0.52% | — | 1 ago 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through… |
| CVE-2024-39619 | Crítica (9.8) | 0.55% | — | 1 ago 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through… |
| CVE-2020-36723 | Media (5.3) | 1.6% | — | 7 jun 2023 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for… |
| CVE-2020-36719 | Crítica (9.8) | 4.3% | — | 7 jun 2023 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the… |
| CVE-2019-19542 | Media (5.4) | 0.72% | — | 26 dic 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page. |
| CVE-2019-19541 | Media (5.4) | 0.72% | — | 26 dic 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page. |
| CVE-2019-19540 | Media (6.1) | 0.93% | — | 26 dic 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. |