The Amtythumb Project maintains a focused image-thumbnail utility with a vulnerability footprint centered on application-layer input handling, where the recurring signal reflects cross-site scripting and SQL injection weaknesses typical of web-facing processing. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amtythumb Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17059MEDIUM XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php. | Nov 29, 2017 | 6.1 | 31 | NO | YES |
CVE-2022-1683HIGH The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement via its shortcode, leading to an SQL injection and is explo | Jun 8, 2022 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amtythumb Project.
Media articles that mention a CVE ID that affects a product developed by Amtythumb Project — matched by CVE ID, not by vendor name.