Emarketdesign
Emarketdesign Request A Quote: vulnerabilidades y CVE
Emarketdesign Request A Quote tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90988 | Media (5.3) | 0.14% | — | 2 oct 2026 | The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request… |
| CVE-2026-14249 | Alta (7.5) | 0.56% | — | 2 jul 2026 | The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function… |
| CVE-2025-64248 | Media (4.3) | 0.22% | — | 16 dic 2025 | Missing Authorization vulnerability in emarket-design Request a Quote request-a-quote allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Request a Quote: from n/a through <= 2.5.3. |
| CVE-2025-58915 | Media (6.5) | 0.17% | — | 23 sept 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Request a Quote request-a-quote allows Stored XSS.This issue affects Request a Quote: from n/a through… |
| CVE-2024-6231 | Media (5.9) | 0.37% | — | 23 jul 2024 | The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2022-2240 | Alta (8.8) | 1.4% | — | 25 jul 2022 | The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin… |
| CVE-2022-2239 | Media (4.8) | 0.64% | — | 25 jul 2022 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html… |
| CVE-2021-24489 | Media (4.8) | 0.64% | — | 25 oct 2021 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the… |
| CVE-2021-24420 | Media (5.4) | 0.62% | — | 12 jul 2021 | The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Emarketdesign
WP Easy Contact · 3Youtube-showcase · 2Youtube Video Gallery · 2Employee Directory Staff Listing Team Directory · 1Employee Spotlight · 1Best Contact Management Software · 1Wp-ticket · 1Event Rsvp AND Simple Event Management · 1Customer Service Software & Support Ticket System · 1EMD Form Builder Lite · 1