Brijeshk89 has a narrowly scoped vulnerability footprint centered on web-based access and management products, specifically IP-based login and smart maintenance mode tools, with vulnerabilities clustering around web-layer input-handling issues including cross-site scripting and cross-site request forgery. The exposure reflects the application-facing attack surface inherent to browser-mediated authentication and administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brijeshk89 over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58960MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login ip-based-login allows Stored XSS.This issue affects | Sep 22, 2025 | 5.9 | 20 | NO | NO |
CVE-2025-50016MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brijeshk89 IP Based Login ip-based-login allows Stored XSS.This issue affects | Jun 20, 2025 | 5.9 | 18 | NO | NO |
CVE-2025-1490MEDIUM The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ parameter in all versions up to, and including, 1.5.2 due to ins | Mar 26, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-12682MEDIUM The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Mar 25, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-13118MEDIUM The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers to make logged in users delete all logs via a CSRF attack | Mar 25, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-12800MEDIUM The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scriptin | May 15, 2025 | 4.8 | 14 | NO | NO |
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored C | Mar 26, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brijeshk89.
Media articles that mention a CVE ID that affects a product developed by Brijeshk89 — matched by CVE ID, not by vendor name.