Adenion's vulnerability profile centers on its Blog2Social product, a social-media management and publishing tool that sits in the content-distribution workflow for web publishers. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, while the recurring weakness classes—cross-site scripting, SQL injection, missing authorization, insecure sensitive-data storage, and server-side request forgery—reflect common attack vectors in web-facing content and credential-handling surfaces. Defenders should prioritize patches for this product where it manages authentication or handles user-supplied publishing content; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adenion over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56044HIGH Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions. | Jun 26, 2026 | 7.1 | 32 | NO | NO |
CVE-2021-24956MEDIUM The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin pag | Dec 21, 2021 | 6.1 | 31 | NO | YES |
CVE-2023-3936MEDIUM The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which coul | Aug 21, 2023 | 6.1 | 30 | NO | YES |
CVE-2019-13572CRITICAL The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. | Aug 1, 2019 | 9.8 | 29 | NO | NO |
CVE-2024-3549CRITICAL The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7. | Jun 11, 2024 | 9.9 | 27 | NO | NO |
CVE-2021-24137HIGH Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary | Mar 18, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-3247MEDIUM The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request | Oct 25, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-3246HIGH The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to | Oct 25, 2022 | 8.8 | 22 | NO | NO |
CVE-2019-17550MEDIUM The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via th | Nov 13, 2019 | 6.1 | 20 | NO | NO |
CVE-2023-40554MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions. | Sep 6, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adenion.
Media articles that mention a CVE ID that affects a product developed by Adenion — matched by CVE ID, not by vendor name.