Kainelabs
Kainelabs Youzify: vulnerabilidades y CVE
Kainelabs Youzify tiene 17 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81275 | Media (6.5) | 0.44% | — | 10 sept 2026 | Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. |
| CVE-2026-73397 | Crítica (9.8) | 0.56% | — | 18 ago 2026 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. |
| CVE-2026-1559 | Media (6.4) | 0.19% | — | 18 abr 2026 | The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping.… |
| CVE-2025-69014 | Media (4.9) | 0.17% | — | 30 dic 2025 | Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.7. |
| CVE-2024-13370 | Media (6.5) | 0.40% | — | 25 ene 2025 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the… |
| CVE-2024-13368 | Media (4.3) | 0.34% | — | 25 ene 2025 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the… |
| CVE-2024-12113 | Media (4.3) | 0.33% | — | 25 ene 2025 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the… |
| CVE-2024-39635 | Alta (8.8) | 0.41% | — | 1 nov 2024 | Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6. |
| CVE-2024-9067 | Media (4.3) | 0.32% | — | 10 oct 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the… |
| CVE-2024-8987 | Media (5.4) | 0.33% | — | 10 oct 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all… |
| CVE-2024-37494 | Alta (8.8) | 0.50% | — | 9 jul 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5. |
| CVE-2024-4742 | Alta (8.8) | 0.50% | — | 20 jun 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and… |
| CVE-2024-2864 | Media (6.1) | 0.35% | — | 25 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify - Buddypress Moderation.This issue affects Youzify - Buddypress Moderation: from n/a through 1.2.5. |
| CVE-2023-47191 | Media (6.5) | 0.43% | — | 21 dic 2023 | Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress… |
| CVE-2023-0059 | Media (5.4) | 0.47% | — | 21 feb 2023 | The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the… |
| CVE-2022-1950 | Crítica (9.8) | 5.9% | — | 1 ago 2022 | The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection |
| CVE-2021-24443 | Media (5.4) | 0.62% | — | 2 ago 2021 | The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.