Awesometogi's vulnerability profile centers on a product-category management tool with a focused attack surface characterized by web-application input-handling issues, specifically cross-site request forgery and cross-site scripting. The recurring weakness classes reflect common vulnerabilities in web-facing interfaces that process and render user-supplied data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Awesometogi over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46151HIGH Cross-Site Request Forgery (CSRF) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions. | Oct 25, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-45054MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions. | Oct 18, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-29173MEDIUM Missing Authorization vulnerability in AWESOME TOGI Product Category Tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Categor | Dec 9, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Awesometogi.
Media articles that mention a CVE ID that affects a product developed by Awesometogi — matched by CVE ID, not by vendor name.