Aeropage develops a focused integration product, Aeropage Sync for Airtable, that bridges data synchronization between platforms and presents a modest vulnerability footprint centered on access-control and file-handling weaknesses. The recurring exposure pattern reflects authorization gaps and unrestricted file-upload risks that are characteristic of data-integration middleware where permission boundaries and upload validation deserve particular attention. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aeropage over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3914HIGH The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all v | Apr 26, 2025 | 8.8 | 32 | NO | NO |
CVE-2025-3915MEDIUM The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'aeropageDeletePost' function in all version | Apr 26, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aeropage.
Media articles that mention a CVE ID that affects a product developed by Aeropage — matched by CVE ID, not by vendor name.