Cleantalk offers anti-spam and firewall protection products deployed across web platforms and content management systems, where its vulnerability profile centers on application-layer input-handling and authorization flaws. The durable signal reflects the vendor's edge-facing role: cross-site scripting, SQL injection, cross-site request forgery, and missing authorization recur across its security appliances, while a meaningful share of vulnerabilities reach serious severity and acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cleantalk over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24295HIGH It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. | May 17, 2021 | 7.5 | 36 | NO | YES |
CVE-2024-10542HIGH The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DN | Nov 26, 2024 | 7.5 | 34 | NO | NO |
CVE-2024-13365CRITICAL The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them fo | Feb 12, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-36698HIGH The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capabili | Oct 20, 2023 | 8.8 | 28 | NO | NO |
CVE-2024-10781HIGH The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'a | Nov 26, 2024 | 7.5 | 27 | NO | NO |
CVE-2023-51535HIGH Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, | Jan 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-3302HIGH The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection e | Oct 25, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-51696HIGH Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, | Feb 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-5239HIGH The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its valu | Nov 27, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-28222MEDIUM The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/Li | Apr 19, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cleantalk.
Media articles that mention a CVE ID that affects a product developed by Cleantalk — matched by CVE ID, not by vendor name.