Cerber develops a security and anti-spam plugin for WordPress that focuses on malware scanning and threat detection across self-hosted WordPress installations. Its disclosed vulnerabilities center on input-handling weaknesses, including cross-site scripting and sensitive-information exposure, which are characteristic of web-facing plugin architectures where user input and configuration data intersect. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cerber over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0429MEDIUM The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugin | Mar 7, 2022 | 6.1 | 26 | NO | YES |
CVE-2022-4712MEDIUM The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. Th | Oct 20, 2023 | 6.1 | 22 | NO | NO |
CVE-2022-2939MEDIUM The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to i | Sep 6, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-4417MEDIUM The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, whi | Jan 2, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cerber.
Media articles that mention a CVE ID that affects a product developed by Cerber — matched by CVE ID, not by vendor name.