Ceikay develops a focused set of content-delivery and user-interface components—including carousel, slideshow, and tooltip widgets—that inject presentation logic into web pages. The vendor's vulnerability exposure centers on cross-site scripting weaknesses arising from improper input neutralization during page generation, a pattern typical of client-side rendering libraries that must balance dynamic content injection with output sanitization. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ceikay over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1335MEDIUM The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Scrip | Jun 13, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-35756MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CeiKay Tooltip CK tooltip-ck allows Stored XSS.This issue affects Toolt | Jun 8, 2024 | 4.8 | 16 | NO | NO |
CVE-2022-1336MEDIUM The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high-privileged users such as admin to perform Cross-Site Script | Jun 13, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ceikay.
Media articles that mention a CVE ID that affects a product developed by Ceikay — matched by CVE ID, not by vendor name.