Castos develops a focused set of podcast hosting and analytics plugins, with a vulnerability profile centered on its Seriously Simple Podcasting and Seriously Simple Stats products. The exposure recurs through web-application weakness classes including cross-site scripting, cross-site request forgery, missing authorization, SQL injection, and sensitive-information disclosure, reflecting the input-handling and access-control demands of WordPress-integrated plugins. A meaningful share of vulnerabilities reach serious severity, and a moderate tendency toward public exploit availability characterizes this vendor's disclosures; live exploitation status and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Castos over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45001CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriousl | Nov 6, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-6444MEDIUM The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated craft | Mar 11, 2024 | 5.3 | 23 | NO | YES |
CVE-2025-49923MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DO | Oct 22, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-66060MEDIUM Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels. | Nov 21, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-66059MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Emb | Nov 21, 2025 | 5.3 | 20 | NO | NO |
CVE-2023-45005MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions. | Oct 17, 2023 | 6.1 | 20 | NO | NO |
CVE-2022-4571MEDIUM The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could al | Jan 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-9667MEDIUM The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all | Nov 5, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8738MEDIUM The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versi | Sep 24, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-25599MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting.This issu | Mar 28, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Castos.
Media articles that mention a CVE ID that affects a product developed by Castos — matched by CVE ID, not by vendor name.