Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bestwebsoft

First CVE: Mar 3, 2015Active for: 11 yearsTotal CVEs: 77
29.2
VTI Score
Low

Bestwebsoft develops a modestly represented portfolio of WordPress plugins and web application extensions, spanning contact-form builders, database connectors, analytics tools, and media galleries that serve small-to-medium web administrators. The vendor's vulnerability profile centers on application-layer input-handling weaknesses characteristic of plugin development: cross-site scripting, SQL injection, and cross-site request forgery recur across its product line, and public exploit code frequently becomes available for these classes. While the severity distribution is moderate, the high tendency toward public exploit availability reflects the appeal of WordPress plugin vulnerabilities to both security researchers and adversaries targeting website infrastructure. Defenders should treat Bestwebsoft plugin updates as part of routine WordPress hardening and monitor for indicators of attack against unpatched instances; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
77
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bestwebsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2015
11 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(59 total)

Top CVEs

Signals from CVEs in this vendor scope (77 CVEs).

77 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-57642HIGH
Contributor SQL Injection in Gallery <= 4.7.8 versions.
Jun 26, 20268.535NONO
CVE-2022-3393CRITICAL
The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection
Oct 25, 20229.831NONO
CVE-2021-24966MEDIUM
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, i
Mar 14, 20224.930NOYES
CVE-2020-8658HIGH
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to
Feb 6, 20208.830NONO
CVE-2017-18590MEDIUM
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
Aug 27, 20196.130NOYES
CVE-2017-18565MEDIUM
The updater plugin before 1.35 for WordPress has multiple XSS issues.
Aug 21, 20196.130NOYES
CVE-2015-9325CRITICAL
The visitors-online plugin before 0.4 for WordPress has SQL injection.
Aug 16, 20199.830NONO
CVE-2017-18564MEDIUM
The sender plugin before 1.2.1 for WordPress has multiple XSS issues.
Aug 21, 20196.129NOYES
CVE-2017-18558MEDIUM
The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
Aug 21, 20196.129NOYES
CVE-2017-18557MEDIUM
The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
Aug 21, 20196.129NOYES
View all 77 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products77 CVEs
75%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network75 (97.4%)
Unknown2 (2.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low75 (97.4%)
High0 (0.0%)
Unknown2 (2.6%)
User Interaction
None17 (22.1%)
Unknown2 (2.6%)
Required58 (75.3%)
Privileges Required
Low9 (11.7%)
High5 (6.5%)
None61 (79.2%)
Unknown2 (2.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (77 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
28 CVEs
36.4% of CVEs· 98th percentile
ExploitDB
1 CVE
1.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bestwebsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bestwebsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bestwebsoft's Products

View all 6 CNAs →

Top CWEs