Davidjmiller maintains a small portfolio of web-based applications including similarity and voting-record tools that present a narrow but recognizable attack surface centered on client-side and request-validation issues. The durable signal across this vendor's disclosures centers on cross-site request forgery and cross-site scripting weaknesses, which are characteristic of web application input handling and state-validation gaps. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Davidjmiller over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7084MEDIUM The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform Stored XSS atta | Jan 16, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-7083MEDIUM The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged | Jan 16, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-3972MEDIUM The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in | Jun 14, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-3971MEDIUM The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CS | Jun 14, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Davidjmiller.
Media articles that mention a CVE ID that affects a product developed by Davidjmiller — matched by CVE ID, not by vendor name.