Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bannersky

First CVE: Jul 14, 2014Active for: 12 yearsTotal CVEs: 12
27.4
VTI Score
Low

Bannersky develops a focused line of WordPress plugins centered around PDF management, form handling, and security blacklisting, which sit in the content-generation and input-processing pathways of websites built on that platform. Its vulnerability profile recurs through application-layer input-handling issues—specifically cross-site scripting and SQL injection—that are characteristic of web-facing form and content-processing components, and the vendor's disclosures have frequently acquired public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bannersky over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2014
12 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-4944MEDIUM
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL comm
Jul 14, 20146.532NOYES
CVE-2026-65528MEDIUM
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
Jul 23, 20266.527NONO
CVE-2021-24860HIGH
The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection iss
Nov 29, 20217.224NONO
CVE-2025-22347HIGH
Cross-Site Request Forgery (CSRF) vulnerability in bannersky BSK Forms Blacklist bsk-gravityforms-blacklist allows Blind SQL Injection.This issue affects BSK Forms Blacklist: from
Jan 7, 20258.223NONO
CVE-2024-47624HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bannersky BSK Forms Blacklist bsk-gravityforms-blacklist allows Reflected XSS.
Oct 5, 20247.121NONO
CVE-2024-43233HIGH
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BannerSky BSK Forms Blacklist allows Reflected XSS.This issue affects B
Aug 12, 20247.121NONO
CVE-2025-4970MEDIUM
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.7.1 due to insufficient input san
Dec 12, 20255.520NONO
CVE-2026-39686MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in bannersky BSK PDF Manager bsk-pdf-manager allows Retrieve Embedded Sensitive Data.This i
Apr 8, 20265.319NONO
CVE-2023-5141MEDIUM
The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflec
Dec 4, 20236.118NONO
CVE-2023-5110MEDIUM
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bsk-pdfm-category-dropdown' shortcode in versions up to, and including, 3.4.1 due to insu
Oct 25, 20235.418NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None4 (33.3%)
Unknown1 (8.3%)
Required7 (58.3%)
Privileges Required
Low2 (16.7%)
High4 (33.3%)
None5 (41.7%)
Unknown1 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bannersky.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bannersky — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bannersky's Products

View all 4 CNAs →

Top CWEs