Davidartiss maintains a focused WordPress plugin portfolio centered on the Code Embed product, which handles embedded content rendering for WordPress sites. The recurring vulnerability signals involve improper input sanitization in web-page generation contexts, leading to cross-site scripting exposure, and uncontrolled resource consumption that can affect site availability. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Davidartiss over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8804MEDIUM The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insuff | Oct 4, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-49837MEDIUM Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6. | Mar 21, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Davidartiss.
Media articles that mention a CVE ID that affects a product developed by Davidartiss — matched by CVE ID, not by vendor name.