Agilelogix maintains a narrowly scoped product portfolio centered on web-based applications such as Store Locator and Post Timeline, which present a modest but concentrated attack surface for web application security. The vendor's vulnerabilities cluster around client-side and request-level weaknesses including cross-site scripting and cross-site request forgery, typical of web application development where input sanitization and token-based protection are critical. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agilelogix over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4151MEDIUM The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scri | Sep 4, 2023 | 6.1 | 29 | NO | YES |
CVE-2023-4284MEDIUM The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scrip | Sep 4, 2023 | 6.1 | 28 | NO | YES |
CVE-2024-13571HIGH The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c | Feb 26, 2025 | 7.1 | 21 | NO | NO |
CVE-2025-24614HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agile Logix Post Timeline post-timeline allows Reflected XSS.This issue affect | Feb 14, 2025 | 7.1 | 21 | NO | NO |
CVE-2022-4832MEDIUM The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2026-32421MEDIUM Missing Authorization vulnerability in Agile Logix Post Timeline post-timeline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Timel | Mar 13, 2026 | 5.3 | 19 | NO | NO |
CVE-2023-27618MEDIUM Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions. | Jun 22, 2023 | 4.8 | 16 | NO | NO |
CVE-2022-41615MEDIUM Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress. | Nov 18, 2022 | 6.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agilelogix.
Media articles that mention a CVE ID that affects a product developed by Agilelogix — matched by CVE ID, not by vendor name.