Bracketspace develops a focused line of WordPress plugins including cron management, notification, and note-taking utilities, with observed vulnerabilities centered on web-application input handling and authorization controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bracketspace over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2186MEDIUM The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks e | Jul 17, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-25084MEDIUM The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, | Feb 7, 2022 | 4.3 | 18 | NO | NO |
CVE-2021-39340MEDIUM The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/class | Nov 1, 2021 | 4.8 | 18 | NO | NO |
The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | May 15, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bracketspace.
Media articles that mention a CVE ID that affects a product developed by Bracketspace — matched by CVE ID, not by vendor name.