Back2nature's vulnerability profile centers on its Word Balloon product, a web-based communication tool where the observed weakness classes—cross-site request forgery and path traversal—reflect typical input-handling and access-boundary risks in web applications. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Back2nature over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4751MEDIUM The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-5884MEDIUM The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete | Dec 4, 2023 | 6.5 | 19 | NO | NO |
CVE-2024-35781MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allows PHP Local File Inclusion.This issue affects Word Balloon: | Jun 21, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Back2nature.
Media articles that mention a CVE ID that affects a product developed by Back2nature — matched by CVE ID, not by vendor name.