Find AND Replace ALL Project
Find AND Replace ALL Project Find AND Replace ALL: vulnerabilidades y CVE
Find AND Replace ALL Project Find AND Replace ALL tiene 2 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE2
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-3850 | Media (4.3) | 0.28% | — | 28 nov 2022 | The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack |
| CVE-2022-2311 | Media (6.1) | 0.51% | — | 28 nov 2022 | The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue. |