Awesome Weather Widget Project maintains a focused, single-product line centered on its weather widget component, which despite modest disclosure volume is more visible than typical in its niche. The observed vulnerability signal clusters around cross-site scripting stemming from improper input neutralization during web page generation, reflecting the product's web-facing presentation layer. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Awesome Weather Widget Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24474MEDIUM The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cro | Aug 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-4944MEDIUM The Awesome Weather Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insuffic | Sep 14, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Awesome Weather Widget Project.
Media articles that mention a CVE ID that affects a product developed by Awesome Weather Widget Project — matched by CVE ID, not by vendor name.