Apidaze provides a web-based communications platform centered on its Widget4Call product, a narrow but specialized offering in the voice and communications space. The disclosed vulnerabilities reflect input-handling weaknesses characteristic of web applications, specifically cross-site scripting issues in page generation. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apidaze over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13099MEDIUM The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou | Feb 1, 2025 | 5.4 | 25 | NO | YES |
CVE-2024-5727MEDIUM The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou | Jun 28, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apidaze.
Media articles that mention a CVE ID that affects a product developed by Apidaze — matched by CVE ID, not by vendor name.