Cardozatechnologies has a focused vulnerability footprint centered on WordPress plugins including WordPress Poll and Cardoza 3D Tag Cloud, with the durable signal dominated by application-layer input-handling and state-management flaws such as SQL injection and cross-site request forgery. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cardozatechnologies over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1401CRITICAL Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to | Feb 13, 2020 | 9.8 | 31 | NO | NO |
CVE-2013-1400CRITICAL Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id paramet | Feb 13, 2020 | 9.8 | 25 | NO | NO |
CVE-2022-41990HIGH Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8. | Jan 17, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cardozatechnologies.
Media articles that mention a CVE ID that affects a product developed by Cardozatechnologies — matched by CVE ID, not by vendor name.