Boxystudio maintains a focused product line of web applications including Cooked and Booked that serve modestly scoped deployment bases. The vendor's vulnerability profile concentrates on application-layer input and output handling, with recurring issues around cross-site request forgery, cross-site scripting, sensitive information exposure, and encoding defects that are characteristic of web application codebases. Current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boxystudio over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3900CRITICAL The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an u | Dec 12, 2022 | 9.8 | 40 | NO | NO |
CVE-2024-49290HIGH Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a before 1.8.0. | Oct 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39681HIGH Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missin | Jul 18, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39680HIGH Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missin | Jul 18, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39679HIGH Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missin | Jul 18, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-39678HIGH Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect | Jul 18, 2024 | 8.8 | 23 | NO | NO |
CVE-2021-24233MEDIUM The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output | Apr 22, 2021 | 6.1 | 20 | NO | NO |
CVE-2022-36399HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointmen | Dec 28, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-44477MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions. | Oct 2, 2023 | 5.4 | 18 | NO | NO |
CVE-2024-41816MEDIUM Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to | Aug 5, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boxystudio.
Media articles that mention a CVE ID that affects a product developed by Boxystudio — matched by CVE ID, not by vendor name.