Cridio's vulnerability footprint centers on ListingPro, a focused real-estate listing and directory platform, where exposure concentrates in application-layer input-handling and access-control issues including path traversal, cross-site scripting, SQL injection, cross-site request forgery, and sensitive-information exposure. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the web-application nature of the product and the attack surface presented by user input processing and authentication boundaries. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cridio over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36719CRITICAL The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due | Jun 7, 2023 | 9.8 | 39 | NO | YES |
CVE-2024-39619CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue | Aug 1, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-39622CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects Lis | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-38795CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affe | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2020-36723MEDIUM The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. | Jun 7, 2023 | 5.3 | 27 | NO | YES |
CVE-2024-39620HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affe | Aug 29, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-39624HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affect | Aug 1, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-39623HIGH Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through <= 2.9.4. | Jan 2, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-39621HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue | Aug 1, 2024 | 7.2 | 21 | NO | NO |
CVE-2019-19540MEDIUM The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. | Dec 26, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cridio.
Media articles that mention a CVE ID that affects a product developed by Cridio — matched by CVE ID, not by vendor name.