Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Amentotech

First CVE: Aug 9, 2021Active for: 5 yearsTotal CVEs: 8

Amentotech's vulnerability footprint centers on Workreap, a freelance marketplace and project-management platform, and skews strongly toward critical-severity outcomes reflecting the platform's web-application nature and exposure of user authentication, authorization, and data-handling functions. The vendor's disclosures frequently acquire public exploit code and recur through authentication bypasses, missing authorization checks, unrestricted file uploads, and cross-site request forgery vulnerabilities—classic web-application attack vectors that compound on a multi-tenant marketplace architecture where privilege separation is essential. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Amentotech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 9, 2021
4 years ago
Most Recent CVE
Jun 12, 2025
407 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24499CRITICAL
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request
Aug 9, 20219.881NOYES
CVE-2025-4973CRITICAL
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1.
Jun 12, 20259.828NONO
CVE-2025-5012HIGH
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the
Jun 12, 20258.826NONO
CVE-2022-3846HIGH
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read any user's notification (employer or freelancer) as the notifi
Dec 5, 20227.525NONO
CVE-2021-24501HIGH
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifyin
Aug 9, 20218.125NONO
CVE-2021-24500HIGH
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated.
Aug 9, 20218.125NONO
CVE-2024-13446CRITICAL
The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly val
Mar 12, 20259.824NONO
CVE-2022-4239MEDIUM
The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request, or indeed that it is an addon service, when processing the
Dec 26, 20226.517NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
50%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None5 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Amentotech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Amentotech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Amentotech's Products

View all 2 CNAs →

Top CWEs