Lucene search

K

Tablepress Security Vulnerabilities

cve
cve

CVE-2024-4354

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, with author-level access and above, to make web...

6.4CVSS

6.6AI Score

0.001EPSS

2024-06-07 06:15 AM
24
cve
cve

CVE-2024-23825

TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. That user input is filtered insufficiently, which makes it is possible to send requests to unintended network locations and receive responses. On...

4.9CVSS

5.2AI Score

0.0005EPSS

2024-01-30 05:15 PM
118
cve
cve

CVE-2019-20180

The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not...

6.8CVSS

6.8AI Score

0.002EPSS

2020-01-09 09:15 PM
100
cve
cve

CVE-2017-10889

TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified...

4.3CVSS

4.4AI Score

0.0005EPSS

2017-11-17 02:29 PM
46