Conversios develops a WooCommerce e-commerce plugin and related integrations, with the observed vulnerability footprint centered on web-application input-handling issues: SQL injection, cross-site scripting, and cross-site request forgery. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Conversios over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1203HIGH The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'valueData' paramete | Mar 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-24952HIGH The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action befo | Mar 7, 2022 | 8.8 | 25 | NO | NO |
CVE-2023-46094MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Conversios Track Google Analytics 4, Facebook Pixel & Conversions API via Google Tag Manager for WooCommerce plugin <= | Oct 26, 2023 | 6.1 | 19 | NO | NO |
CVE-2022-46797MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin <= 5.2.3 leads to plugin settings | Mar 1, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Conversios.
Media articles that mention a CVE ID that affects a product developed by Conversios — matched by CVE ID, not by vendor name.