目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

boldgrid 厂商漏洞列表 / CVE 中文分析 43

boldgrid 厂商相关 43 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

BoldGrid 是一家专注于 WordPress 生态的开发商,提供网站构建工具及主题插件服务。其软件历史上频繁出现远程代码执行、跨站脚本及越权访问等高危漏洞,累计已收录 43 条 CVE。这些缺陷多源于输入验证不足或权限逻辑缺陷,易导致数据泄露或服务器被控。鉴于其广泛的用户基数,相关漏洞修复需及时跟进,以保障网站基础设施的安全稳定运行。

CVE IDタイトルCVSS深刻度公開日
CVE-2023-5359 W3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext — W3 Total CacheCWE-200 3.7 Low2024-09-24
CVE-2024-6848 Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload — Post and Page Builder by BoldGrid – Visual Drag and Drop EditorCWE-79 6.4 Medium2024-07-20
CVE-2024-24869 WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerability — Total UpkeepCWE-22 7.5 High2024-05-17
CVE-2024-4400 Post and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.4 - Authenticated (Contributer+) Stored Cross-Site Scripting — Post and Page Builder by BoldGrid – Visual Drag and Drop EditorCWE-79 6.4 Medium2024-05-16
CVE-2024-2950 BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure — BoldGrid Easy SEO – Simple and Effective SEOCWE-200 5.3 Medium2024-04-06
CVE-2024-1692 BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.13 - Authenticated(Contributor+) Stored Cross-Site Scripting via Meta Description — BoldGrid Easy SEO – Simple and Effective SEOCWE-79 6.4 Medium2024-03-30
CVE-2024-2888 WordPress Post and Page Builder by BoldGrid plugin <= 1.26.2 - Cross Site Scripting (XSS) vulnerability — Post and Page Builder by BoldGrid – Visual Drag and Drop EditorCWE-79 6.5 Medium2024-03-26
CVE-2024-0386 weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer — weForms – Easy Drag & Drop Contact Form Builder For WordPressCWE-79 7.2 High2024-03-12
CVE-2023-25480 WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF) — Post and Page Builder by BoldGrid – Visual Drag and Drop EditorCWE-352 4.3 Medium2023-10-06
CVE-2022-4932 Total Upkeep <= 1.14.13 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure — Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGridCWE-862 4.3 Medium2023-03-07
CVE-2021-24452 W3 Total Cache < 2.1.5 - Reflected XSS in Extensions Page (JS Context) — W3 Total CacheCWE-79 6.1 -2021-07-19
CVE-2021-24436 W3 Total Cache < 2.1.4 - Reflected XSS in Extensions Page (Attribute Context) — W3 Total CacheCWE-79 6.1 -2021-07-19
CVE-2021-24427 W3 Total Cache < 2.1.3 - Authenticated Stored XSS — W3 Total CacheCWE-79 4.8 -2021-07-12

本页汇总了 boldgrid 厂商截至目前公开的全部 43 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。