GithubHelp home page GithubHelp logo

cve-id-reports's Introduction

CVE Reports for DWS

Responsible disclosure

This repository follows the Responsible Disclosure model and discloses the vulnerable details after a period of time. During this period, I try to contact the author of the vulnerable plugins and help them to patch or mitigate the issue. The disclosure period is 15 days If I don't get the response from the original author. After than period, I wll open all details about the vulnerability. When the connection is established the release date depends on the discussion.

Intoduction

This repository will present all verified or suspected vulnerable dynamic web service(DWS) including Wordpress Plugin, Joomla Extension, and some CMS published in Github. I say "verified" means that the vulnerability report got the CVE ID from WPScan but "suspected" is not equal to Safe For Use.

CVE List

DWS(WrodPress Plugins, Joomla Extension, and CMS in Github)

Plateform DWS CVE-ID
WordPress WP-Curricul Vitea Free CVE-2021-24222
WordPress N5 Upload Form CVE-2021-24223
WordPress Easy Form Builder CVE-2021-24224
WordPress Imagement CVE-2021-24236
WordPress College Publisher Import CVE-2021-24253
WordPress Event Banner CVE-2021-24251
WordPress Classyfrieds CVE-2021-24252
WordPress Fileviewer CVE-2021-24491
WordPress Email Artillery CVE-2021-24490

Detecting New Vulnerable WordPress Plugins

Recently, we detected total 20+ vulnerable WordPress Plugins that are available to download. Our testing wordpress is version 5.3.8. Some of the plugins are not be installed under default environment of this version or newer one.

cve-id-reports's People

Contributors

jinhuang1102 avatar

Stargazers

 avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.