Extension WordPress
Vulnérabilités Insert Special Characters
Cette page rassemble les failles publiées pour Insert Special Characters, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Insert Special Characters
9 fiches
simple-git < 3.15.0 – Remote Code Execution
The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package,…
*-1.0.5
1.0.6
05/12/2022
loader-utils (JS package) < 2.0.3 – Prototype Pollution
The package loader-utils before 1.4.1, from 2.0.0 and before 2.0.3 is vulnerable to prototype pollution via the function parseQuery which could make injecting malicious web scripts possible in some cases.
*-1.0.5
1.0.6
12/10/2022
loader-utils (JS package) < 3.2.1 – Regular Expression Denial of Service
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the resourcePath variable due to insecure usage of regular…
*-1.0.5
1.0.6
11/10/2022
loader-utils (JS package) < 3.2.1 – Regular Expression Denial of Service
The package loader-utils before 1.4.2, from 2.0.0 and before 2.0.4 as well as versions from 3.0.0 but below 3.2.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the interpolateName function due to insecure usage of regular…
*-1.0.5
1.0.6
11/10/2022
guzzlehttp/psr7 <= 1.84 and 2.0.0-2.1.0 – Improper Input Validation
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4…
*-1.0.4
1.0.5
19/07/2022
semver-regex <= 3.1.3 and 4.0.0-4.0.3 – Regular Expression Denial of Service (ReDoS)
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method. Some WordPress plugins and themes use this dependency though…
*-1.0.4
1.0.5
13/05/2022
async <= 2.6.3 and 3-3.2.2 – Prototype Pollution
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin…
*-1.0.4
1.0.5
07/04/2022
Minimist <= 1.2.5 – Prototype Pollution
Minimist
*-1.0.4
1.0.5
18/03/2022
ansi-regex >=2.1.1 <3.0.1 >=4.0.0 <4.1.1 >=5.0.0 <5.0.1 >=6.0.0 <6.0.1 – Regular Expression Denial of Service (ReDoS)
ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
*-1.0.4
1.0.5
09/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.