| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-55205 | Capsule tenant owners with "patch namespace" permission can hijack system namespaces label | projectcapsule | capsule | Critical | 9.0 | 2025-08-18 16:28:51 | Deep Dive |
| CVE-2025-47477 | WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.23 - Reflected Cross Site Scripting (XSS) vulnerability | revmakx | Backup and Staging by WP Time Capsule | High | 7.1 | 2025-06-09 15:54:12 | Deep Dive |
| CVE-2024-8856 | Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload | revmakx | Backup and Staging by WP Time Capsule | Critical | 9.8 | 2024-11-16 04:29:16 | Deep Dive |
| CVE-2024-49684 | WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.21 - PHP Object Injection vulnerability | revmakx | Backup and Staging by WP Time Capsule | High | 7.2 | 2024-10-23 15:13:56 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-48020 | WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.21 - SQL Injection vulnerability | revmakx | Backup and Staging by WP Time Capsule | High | 8.5 | 2024-10-11 18:15:02 | Deep Dive |
| CVE-2024-39690 | Capsule tenant owner with "patch namespace" permission can hijack system namespaces | projectcapsule | capsule | High | 8.4 | 2024-08-20 14:33:25 | Deep Dive |
| CVE-2024-38770 | WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.20 - Authentication Bypass and Privilege Escalation Vulnerability | Revmakx | Backup and Staging by WP Time Capsule | Critical | 9.8 | 2024-08-01 20:57:05 | Deep Dive |
| CVE-2023-48312 | Authentication bypass using an empty token in capsule-proxy | projectcapsule | capsule-proxy | Critical | 9.8 | 2023-11-24 17:12:40 | Deep Dive |
| CVE-2023-46254 | Service accounts can see namespaces of other tenants in capsule-proxy | projectcapsule | capsule-proxy | Medium | 4.3 | 2023-11-06 18:34:14 | Deep Dive |
| CVE-2022-46167 | Capsule vulnerable to privilege escalation by ServiceAccount deployed in a Tenant Namespace | clastix | capsule | High | 8.8 | 2022-12-02 18:22:22 | Deep Dive |
| CVE-2022-23745 | Capsule Technologies Capsule Workspace 缓冲区错误漏洞 | - | Checkpoint Harmony Capsule Workspace | 高危 | - | 2022-07-18 16:09:20 | Deep Dive |
| CVE-2022-23652 | Privilege escalation using hop-by-hop Connection header | clastix | capsule-proxy | High | 8.8 | 2022-02-22 19:55:11 | Deep Dive |
| CVE-2021-25035 | Backup and Staging by WP Time Capsule < 1.22.7 - Reflected Cross-Site Scripting | Unknown | Backup and Staging by WP Time Capsule | 中危 | - | 2022-01-24 08:01:15 | Deep Dive |
| CVE-2019-5024 | Capsule Technologies SmartLinx Neuron 输入验证错误漏洞 | Capsule Technologies | Capsule Technologies SmartLinx Neuron 2 | 高危 | - | 2019-04-11 17:45:08 | Deep Dive |