Connections Pro maintains a narrow portfolio centered on business directory and content management components, with a small disclosed vulnerability footprint. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Connections Pro over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36503HIGH The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue | Nov 1, 2021 | 8.0 | 25 | NO | NO |
CVE-2024-13926HIGH The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post containing a large number of tags, thereby exploiting a catastrophi | Apr 19, 2025 | 7.5 | 22 | NO | NO |
CVE-2021-24794MEDIUM The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cro | Nov 1, 2021 | 4.8 | 18 | NO | NO |
CVE-2023-29437MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions. | Jun 26, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Connections Pro.
Media articles that mention a CVE ID that affects a product developed by Connections Pro — matched by CVE ID, not by vendor name.