Apptha develops WordPress video-gallery plugins and related multimedia components, with the observed vulnerability signal centered on application-layer input handling, specifically SQL injection and cross-site scripting flaws in web-facing gallery interfaces. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apptha over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2065HIGH SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute a | Feb 24, 2015 | 7.5 | 59 | NO | YES |
CVE-2014-9097HIGH Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) r | Nov 26, 2014 | 7.5 | 30 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote | Nov 26, 2014 | 3.5 | 20 | NO | YES |
CVE-2013-3478HIGH SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid parameter | Mar 5, 2014 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apptha.
Media articles that mention a CVE ID that affects a product developed by Apptha — matched by CVE ID, not by vendor name.