Awsm develops a focused portfolio of web-based productivity and hiring tools including Awsm Team, Embed Any Document, and WP Job Openings, with a documented exposure pattern centered on web application security controls. The recurring vulnerability classes—encompassing path traversal, cross-site scripting, improper file upload validation, and inadequate access restrictions—reflect common gaps in input sanitization and resource access control in web-facing applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Awsm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-37454HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AWSM Innovations AWSM Team allows Path Traversal.This issue affects AWSM Team: from | Jul 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-4933MEDIUM The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated v | Oct 16, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-23707MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Do | Mar 23, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Awsm.
Media articles that mention a CVE ID that affects a product developed by Awsm — matched by CVE ID, not by vendor name.