Newstatpress Project
Newstatpress Project Newstatpress: vulnerabilidades y CVE
Newstatpress Project Newstatpress tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-20094 | Media (5.4) | 0.59% | — | 24 jun 2022 | A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The… |
| CVE-2022-0206 | Media (6.1) | 1.5% | — | 14 feb 2022 | The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues |
| CVE-2017-18575 | Media (6.1) | 0.92% | — | 22 ago 2019 | The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues. |
| CVE-2015-9315 | Crítica (9.8) | 1.8% | — | 14 ago 2019 | The newstatpress plugin before 1.0.1 for WordPress has SQL injection. |
| CVE-2015-9314 | Media (6.1) | 0.92% | — | 14 ago 2019 | The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. |
| CVE-2015-9313 | Crítica (9.8) | 1.8% | — | 14 ago 2019 | The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. |
| CVE-2015-9312 | Media (6.1) | 1.8% | — | 14 ago 2019 | The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element. |
| CVE-2015-9311 | Media (6.1) | 0.92% | — | 14 ago 2019 | The newstatpress plugin before 1.0.6 for WordPress has reflected XSS. |
| CVE-2015-4063 | Baja (3.5) | 6.1% | — | 27 may 2015 | Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter… |
| CVE-2015-4062 | Media (6.5) | 9.1% | — | 27 may 2015 | SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search… |