Bologer maintains AnyComment, a web-based engagement and commenting platform whose vulnerability footprint centers on application-layer issues typical of interactive web services. The recurring weakness classes—race conditions, cross-site request forgery, cross-site scripting, and open redirects—reflect the input handling and session-management demands of a user-facing commenting system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bologer over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24838MEDIUM The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, lea | Jan 17, 2022 | 6.1 | 32 | NO | YES |
CVE-2022-0134HIGH The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such act | Feb 21, 2022 | 8.8 | 22 | NO | NO |
CVE-2018-21001MEDIUM The anycomment plugin before 0.0.33 for WordPress has XSS. | Aug 27, 2019 | 6.1 | 18 | NO | NO |
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their | Feb 21, 2022 | 3.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bologer.
Media articles that mention a CVE ID that affects a product developed by Bologer — matched by CVE ID, not by vendor name.