Admincolumns provides a WordPress plugin that facilitates admin-interface customization and data presentation, with its vulnerability footprint centered on this single product. The durable signal reflects web-application input-handling patterns: CSV formula injection and cross-site scripting weaknesses that are characteristic of user-facing data processing and display functionality.
The number and severity of CVEs published that impact products developed by Admincolumns over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17661HIGH A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula | Nov 8, 2019 | 8.8 | 28 | NO | NO |
CVE-2021-24365MEDIUM The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowe | Jul 12, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24366MEDIUM The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and escape its Label settings, which could allow high privilege us | Jun 21, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Admincolumns.
Media articles that mention a CVE ID that affects a product developed by Admincolumns — matched by CVE ID, not by vendor name.