Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Badgeos

First CVE: May 9, 2022Active for: 4 yearsTotal CVEs: 7

Badgeos is a gamification platform for WordPress that provides badge and achievement management across learning and engagement applications, with a comparatively narrow product footprint. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, while clustering around web-application fundamentals: authorization bypass through user-controlled keys, SQL injection, cross-site request forgery, cross-site scripting, and missing authorization checks that are typical of plugin and CMS-extension ecosystems. Defenders should treat Badgeos disclosures as application-layer priorities for affected WordPress deployments; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Badgeos over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2022
4 years ago
Most Recent CVE
Aug 31, 2023
1,058 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0817CRITICAL
The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable b
May 9, 20229.842NOYES
CVE-2022-2958HIGH
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leadi
Sep 19, 20228.828NONO
CVE-2022-41987HIGH
Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.
May 25, 20238.827NONO
CVE-2023-2171MEDIUM
The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.7.1.6 due to insufficient input sani
Aug 31, 20235.418NONO
CVE-2023-2174MEDIUM
The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to,
Aug 31, 20234.315NONO
CVE-2023-2173MEDIUM
The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization c
Aug 31, 20234.315NONO
CVE-2023-2172MEDIUM
The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization c
Aug 31, 20234.314NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
29%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low5 (71.4%)
High0 (0.0%)
None2 (28.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Badgeos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Badgeos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Badgeos's Products

View all 3 CNAs →

Top CWEs