Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Castos

First CVE: Sep 23, 2022Active for: 4 yearsTotal CVEs: 15
25.1
VTI Score
Low

Castos develops a focused set of podcast hosting and analytics plugins, with a vulnerability profile centered on its Seriously Simple Podcasting and Seriously Simple Stats products. The exposure recurs through web-application weakness classes including cross-site scripting, cross-site request forgery, missing authorization, SQL injection, and sensitive-information disclosure, reflecting the input-handling and access-control demands of WordPress-integrated plugins. A meaningful share of vulnerabilities reach serious severity, and a moderate tendency toward public exploit availability characterizes this vendor's disclosures; live exploitation status and severity counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Castos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2022
3 years ago
Most Recent CVE
Nov 21, 2025
245 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-45001CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriousl
Nov 6, 20239.826NONO
CVE-2023-6444MEDIUM
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated craft
Mar 11, 20245.323NOYES
CVE-2025-49923MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DO
Oct 22, 20256.121NONO
CVE-2025-66060MEDIUM
Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.
Nov 21, 20255.320NONO
CVE-2025-66059MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Emb
Nov 21, 20255.320NONO
CVE-2023-45005MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions.
Oct 17, 20236.120NONO
CVE-2022-4571MEDIUM
The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could al
Jan 16, 20235.420NONO
CVE-2024-9667MEDIUM
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all
Nov 5, 20246.118NONO
CVE-2024-8738MEDIUM
The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versi
Sep 24, 20246.118NONO
CVE-2024-25599MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting.This issu
Mar 28, 20246.118NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
93%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High1 (6.7%)
Unknown0 (0.0%)
User Interaction
None4 (26.7%)
Unknown0 (0.0%)
Required11 (73.3%)
Privileges Required
Low2 (13.3%)
High2 (13.3%)
None11 (73.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Castos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Castos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Castos's Products

View all 3 CNAs →

Top CWEs