Danialhatami's vulnerability footprint centers on a narrowly scoped set of web-accessible tools, specifically FTP access utilities and Persian font packages, where the observed exposure reflects application-layer input-handling issues characteristic of web-facing components. The recurring weakness class involves improper neutralization of user input in web page generation contexts, a pattern typical of tools that process or display untrusted content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Danialhatami over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7167MEDIUM The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | Feb 27, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-3510MEDIUM The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing | Sep 11, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Danialhatami.
Media articles that mention a CVE ID that affects a product developed by Danialhatami — matched by CVE ID, not by vendor name.