CVE-2025-60227
- EPSS 0.1%
- Veröffentlicht 22.10.2025 14:32:46
- Zuletzt bearbeitet 20.01.2026 15:17:35
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.This issue affects WP Pipes: from n/a through <= 1.4.3.
CVE-2025-28977
- EPSS 0.02%
- Veröffentlicht 20.08.2025 08:03:48
- Zuletzt bearbeitet 01.12.2025 17:58:07
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This issue affects WP Pipes: from n/a through 1.4.3.
CVE-2025-28979
- EPSS 0.11%
- Veröffentlicht 14.08.2025 10:34:33
- Zuletzt bearbeitet 01.12.2025 18:07:07
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PHP Local File Inclusion. This issue affects WP Pipes: from n/a through 1.4.3.
CVE-2025-28982
- EPSS 0.04%
- Veröffentlicht 16.07.2025 11:28:11
- Zuletzt bearbeitet 26.11.2025 14:38:19
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.
CVE-2025-48267
- EPSS 0.09%
- Veröffentlicht 09.06.2025 15:53:55
- Zuletzt bearbeitet 26.11.2025 15:16:02
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue affects WP Pipes: from n/a through 1.4.2.
CVE-2025-47664
- EPSS 0.16%
- Veröffentlicht 07.05.2025 14:20:48
- Zuletzt bearbeitet 26.11.2025 17:09:00
Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.
CVE-2024-12283
- EPSS 1.91%
- Veröffentlicht 11.12.2024 09:15:05
- Zuletzt bearbeitet 26.11.2025 12:46:13
The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate...
CVE-2023-40009
- EPSS 0.05%
- Veröffentlicht 03.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:18:30
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions.
CVE-2022-45355
- EPSS 0.35%
- Veröffentlicht 29.03.2023 19:15:21
- Zuletzt bearbeitet 21.11.2024 07:29:05
Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.