« Volver al listado

Kainelabs

Kainelabs Youzify: vulnerabilidades y CVE

Kainelabs Youzify tiene 17 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses4
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81275Media (6.5)0.44%—10 sept 2026
Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
CVE-2026-73397Crítica (9.8)0.56%—18 ago 2026
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
CVE-2026-1559Media (6.4)0.19%—18 abr 2026
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping.…
CVE-2025-69014Media (4.9)0.17%—30 dic 2025
Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.7.
CVE-2024-13370Media (6.5)0.40%—25 ene 2025
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the…
CVE-2024-13368Media (4.3)0.34%—25 ene 2025
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the…
CVE-2024-12113Media (4.3)0.33%—25 ene 2025
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the…
CVE-2024-39635Alta (8.8)0.41%—1 nov 2024
Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.
CVE-2024-9067Media (4.3)0.32%—10 oct 2024
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the…
CVE-2024-8987Media (5.4)0.33%—10 oct 2024
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all…
CVE-2024-37494Alta (8.8)0.50%—9 jul 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.
CVE-2024-4742Alta (8.8)0.50%—20 jun 2024
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and…
CVE-2024-2864Media (6.1)0.35%—25 mar 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify - Buddypress Moderation.This issue affects Youzify - Buddypress Moderation: from n/a through 1.2.5.
CVE-2023-47191Media (6.5)0.43%—21 dic 2023
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress…
CVE-2023-0059Media (5.4)0.47%—21 feb 2023
The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the…
CVE-2022-1950Crítica (9.8)5.9%—1 ago 2022
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
CVE-2021-24443Media (5.4)0.62%—2 ago 2021
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1078 Valid Accounts1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.