We have discovered 1,259,392 live websites that are affected by CWE-284.
![]() | 396,981 websites |
![]() | 145,772 websites |
![]() | 75,368 websites |
![]() | 45,448 websites |
![]() | 45,236 websites |
![]() | 40,095 websites |
![]() | 38,023 websites |
![]() | 32,046 websites |
![]() | 31,585 websites |
![]() | 28,755 websites |
.com | 528,048 websites |
.de | 64,684 websites |
.org | 48,674 websites |
.nl | 36,000 websites |
.ru | 35,033 websites |
.co.uk | 32,800 websites |
.net | 29,749 websites |
.it | 27,432 websites |
.com.br | 27,231 websites |
.fr | 26,375 websites |
Discovered | CVE | Description | Websites |
---|---|---|---|
Mar, 2025 | CVE-2025-25225 | Extension - hikashop.com - Privilege escalation vulnerability Hikashop component version 1.0.0 - 5.1.3 for Joomla | 5,987 |
Mar, 2025 | CVE-2024-13430 | Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode | 13,837 |
Mar, 2025 | CVE-2024-13635 | VK Blocks <= 1.94.2.2 - Missing Authorization to Sensitive Information Exposure | 12,467 |
Mar, 2025 | CVE-2024-56195 | Apache Traffic Server: Intercept plugins are not access controlled | 1,295 |
Mar, 2025 | CVE-2024-56196 | Apache Traffic Server: ACL is not fully compatible with older versions | 64 |
Feb, 2025 | CVE-2024-13693 | Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php | 172,709 |
Feb, 2025 | CVE-2024-13855 | Prime Addons for Elementor <= 2.0.1 - Authenticated (Contributor+) Insecure Direct Object Reference via pae_global_block Shortcode | 10 |
Feb, 2025 | CVE-2024-13854 | Education Addon for Elementor <= 1.3.1 - Authenticated (Contributor+) Insecure Direct Object Reference via naedu_elementor_template Shortcode | 27 |
Feb, 2025 | CVE-2025-0968 | ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function | 162,893 |
Feb, 2025 | CVE-2025-24411 | Adobe Commerce | Improper Access Control (CWE-284) | 4,103 |
Discovered | CVE | Description | Websites |
---|---|---|---|
Apr, 2024 | CVE-2024-1310 | WooCommerce < 8.6 - Contributor+ Private/Draft Products Access | 536,829 |
May, 2020 | CVE-2020-11028 | Unauthenticated disclosure of certain private posts in WordPress | 252,236 |
Feb, 2025 | CVE-2024-13693 | Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php | 172,709 |
Feb, 2025 | CVE-2025-0968 | ElementsKit Elementor addons <= 3.4.0 - Unauthenticated Information Exposure via get_megamenu_content Function | 162,893 |
Oct, 2022 | CVE-2021-36913 | Redirection for Contact Form 7 <= 2.4.0 - Unauthenticated Options Change and Content Injection vulnerability | 49,764 |
Mar, 2024 | CVE-2024-1564 | Schema Pro < 2.7.16 - Contributor+ Custom Field Access | 14,522 |
Jan, 2025 | CVE-2024-13457 | Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure | 14,297 |
Mar, 2025 | CVE-2024-13430 | Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode | 13,837 |
Mar, 2025 | CVE-2024-13635 | VK Blocks <= 1.94.2.2 - Missing Authorization to Sensitive Information Exposure | 12,467 |
May, 2023 | CVE-2023-1524 | Download Manager < 3.2.71 - Broken Access Controls | 7,790 |
Domain | Country | Rank | Contacts |
---|---|---|---|
**.*********.org | ![]() | ** | |
*******.com | ![]() | ** | |
****.******.com | ![]() | *** | |
********.****.com | ![]() | *** | |
**.*********.org | ![]() | *** | |
*******.*********.org | ![]() | *** | |
**.*********.org | ![]() | *** | |
*********.net | ![]() | *** | |
*********.org | ![]() | *,*** | |
*********.org | ![]() | *,*** |