Cartpauj develops a narrow line of web-based forum and redirect plugins characterized by application-layer input-handling weaknesses. The durable signal centers on SQL injection, cross-site scripting, and cross-site request forgery vulnerabilities that recur across products including Mingle Forum and Shortcode Redirect, typical of server-side web applications handling user input and form submissions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cartpauj over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-0735HIGH Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id p | Apr 2, 2014 | 7.5 | 24 | NO | NO |
CVE-2025-54746MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj Shortcode Redirect shortcode-redirect allows Stored XSS.This issue af | Aug 14, 2025 | 6.5 | 21 | NO | NO |
CVE-2012-5327MEDIUM Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users | Oct 8, 2012 | 6.5 | 21 | NO | NO |
CVE-2013-0736MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication | Oct 9, 2013 | 6.8 | 20 | NO | NO |
CVE-2012-5328MEDIUM Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrar | Oct 8, 2012 | 6.5 | 20 | NO | NO |
CVE-2013-0734MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) | Mar 28, 2014 | 4.3 | 18 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authen | Oct 8, 2012 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cartpauj.
Media articles that mention a CVE ID that affects a product developed by Cartpauj — matched by CVE ID, not by vendor name.