Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

10up

First CVE: Nov 11, 2019Active for: 7 yearsTotal CVEs: 11
16.3
VTI Score
Low

10up is a web development agency with a focused portfolio of WordPress plugins and tools, including products such as Safe SVG, ElasticPress, Restricted Site Access, and Simple Local Avatars that serve publishing and search optimization use cases. The vulnerabilities affecting this vendor center on application-layer weaknesses typical of web-facing PHP code, including cross-site request forgery, cross-site scripting, authorization bypass, and input-handling flaws that recur across its plugin ecosystem. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 10up over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 11, 2019
6 years ago
Most Recent CVE
Aug 12, 2025
346 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-18855HIGH
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
Nov 11, 20197.525NONO
CVE-2019-18854HIGH
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">
Nov 11, 20197.525NONO
CVE-2024-43116HIGH
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
Aug 26, 20248.824NONO
CVE-2022-1613MEDIUM
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-b
Sep 26, 20225.319NONO
CVE-2024-8378MEDIUM
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload
Nov 7, 20244.817NONO
CVE-2023-48753MEDIUM
Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Ac
Jun 4, 20245.317NONO
CVE-2022-1091MEDIUM
The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the POST request to upload a file. Exploiting this vulnerabilit
Apr 18, 20226.117NONO
CVE-2025-8482MEDIUM
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_
Aug 12, 20254.316NONO
CVE-2021-4405MEDIUM
The ElasticPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.3. This is due to missing or incorrect nonce validation on t
Jul 1, 20234.316NONO
CVE-2024-10786MEDIUM
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versio
Nov 16, 20244.315NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
73%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High1 (9.1%)
None8 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 10up.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 10up — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 10up's Products

View all 4 CNAs →

Top CWEs