Known vulnerabilities in All In One WP Security & Firewall
Vendor:
Tips and Tricks HQ
Software:
All In One WP Security & Firewall
Software CPE:
cpe:2.3:a:tips_and_tricks_hq:all-in-one-wp-security-and-firewall:*:*:*:*:*:wordpress:*:*
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.4.4
5.4.3
5.4.2
5.4.1
5.4.0
5.3.10
5.3.8
5.3.7
5.3.6
5.3.5
5.3.4
5.3.3
5.3.2
5.3.1
5.3.0
5.2.9
5.2.8
5.2.7
5.2.6
5.2.5
5.2.4
5.2.3
5.2.2
5.2.1
5.2.0
5.1.9
5.1.8
5.1.7
5.1.6
5.1.5
5.1.4
5.1.3
5.1.2
5.1.1
5.1.0
5.0.9
5.0.8
5.0.7
5.0.6
5.0.5
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.4.12
4.4.11
4.4.10
4.4.9
4.4.8
4.4.6
4.4.5
4.4.4
4.4.3
4.4.2
4.4.1
4.4.0
4.3.9.4
4.3.9.3
4.3.9.2
4.3.9.1
4.3.9
4.3.8.3
4.3.8.2
4.3.8.1
4.3.7.2
4.3.7.1
4.3.1
4.2.9
4.2.8
4.2.2
4.1.7
4.1.4
4.1.0
4.0.9
4.0.8
4.0.7
4.0.3
4.0.1
3.9.9
3.9.6
3.9.5
3.8.7
3.7.7
3.7.6
3.7.5
3.7.3
3.7.1
3.6
3.5.1
3.4
3.3
3.2
3.1
3.0
2.9
2.8.1
2.8
2.7
2.6
2.5
2.4
2.3
2.2
2.1.1
2.0
1.9
1.8
1.7
1.6
1.5
1.4
1.3
1.2
1.1
1.0
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU69617 - Cross-Site Request Forgery (CSRF) CVE-2022-44737 |
CWE-352 | Low | 5.1.1 | 25.11.2022 |
SB2022112524 |
||
| #VU46570 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 4.4.4 | 10.09.2020 |
SB2020091009 |
||
| #VU46569 - Cross-Site Request Forgery (CSRF) |
CWE-352 | Low | 4.4.4 | 10.09.2020 |
SB2020091009 |
||
| #VU21968 - URL Redirection to Untrusted Site ('Open Redirect') |
CWE-601 | Low | 4.4.2 | 21.10.2019 |
SB2019100819 |
||
| #VU20707 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2016-10888 |
CWE-89 | High | 4.0.7 | 02.09.2019 |
SB2016040601 |
||
| #VU20697 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2016-10887 |
CWE-89 | High | 4.0.9 | 02.09.2019 |
SB2016051016 |
||
| #VU20651 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
CWE-79 | Low | 4.2.2 | 02.09.2019 |
SB2016121403 |