Antoineh operates a focused web application environment centered on its football pool product, with observed vulnerabilities clustering around improper input neutralization during web page generation, manifesting as cross-site scripting weaknesses. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Antoineh over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58987MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affects Foot | Sep 9, 2025 | 6.5 | 22 | NO | NO |
CVE-2017-18524MEDIUM The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues. | Aug 20, 2019 | 6.1 | 19 | NO | NO |
CVE-2025-53280MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affects Foot | Jun 27, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-5490MEDIUM The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.4 due to insufficient input saniti | Jun 19, 2025 | 4.8 | 16 | NO | NO |
CVE-2025-30764MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool football-pool allows Cross Site Request Forgery.This issue affects Football Pool: from n/a through <= 2.12 | Mar 27, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Antoineh.
Media articles that mention a CVE ID that affects a product developed by Antoineh — matched by CVE ID, not by vendor name.