Axelerant offers a testimonials widget product with a narrowly scoped vulnerability footprint centered on input-handling weaknesses in web-facing functionality. The recurring signal reflects cross-site scripting flaws typical of client-side rendering components that process user-supplied content. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Axelerant over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24136MEDIUM Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing re | Mar 18, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-37553MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant Testimonials Widget allows Stored XSS.This issue affects Test | Jul 6, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-4705MEDIUM The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to | Jun 6, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Axelerant.
Media articles that mention a CVE ID that affects a product developed by Axelerant — matched by CVE ID, not by vendor name.