Clogica's vulnerability profile centers on a narrow set of WordPress security and SEO redirection plugins, reflecting a focused niche in web application extension development. The recurring weakness classes—cross-site scripting and cross-site request forgery—are characteristic of web-facing plugins that handle user input and administrative functions without sufficient sanitization or token validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clogica over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40695HIGH Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress. | Nov 18, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-24328MEDIUM The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attack | Jun 1, 2021 | 6.2 | 22 | NO | NO |
CVE-2021-24324MEDIUM The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change the plugin's settings. Due to th | May 17, 2021 | 6.5 | 21 | NO | NO |
CVE-2021-24325MEDIUM The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not pr | May 17, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-24327MEDIUM The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboar | May 17, 2021 | 4.8 | 19 | NO | NO |
CVE-2021-24326MEDIUM The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issu | May 17, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24187MEDIUM The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properl | Apr 5, 2021 | 5.4 | 19 | NO | NO |
CVE-2016-10896MEDIUM The seo-redirection plugin before 4.3 for WordPress has stored XSS. | Aug 21, 2019 | 6.1 | 19 | NO | NO |
CVE-2022-38704MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history. | Sep 23, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clogica.
Media articles that mention a CVE ID that affects a product developed by Clogica — matched by CVE ID, not by vendor name.