Artplacer's vulnerability profile centers on its web-based widget product, with the durable signal centered on application-layer security issues including cross-site request forgery, SQL injection, and missing authorization controls. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Artplacer over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67517CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind SQL Injection.This is | Dec 9, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-6373HIGH The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. | Jan 16, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-7269HIGH The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make lo | Jul 19, 2024 | 7.5 | 22 | NO | NO |
CVE-2026-24555MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Stored XSS.This issue affec | Jan 23, 2026 | 6.5 | 20 | NO | NO |
CVE-2023-7268MEDIUM The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delet | Jul 19, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Artplacer.
Media articles that mention a CVE ID that affects a product developed by Artplacer — matched by CVE ID, not by vendor name.