Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Davidlingren

First CVE: Aug 22, 2019Active for: 7 yearsTotal CVEs: 27
50.5
VTI Score
TOP TARGET

Davidlingren's vulnerability footprint centers on a single media-management application and skews toward serious outcomes, with vulnerabilities frequently acquiring public exploit code. The recurring weakness classes—cross-site scripting, SQL injection, sensitive information exposure, and file-path manipulation—reflect common input-handling and access-control gaps in web-facing media-library software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
3.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Davidlingren over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2019
6 years ago
Most Recent CVE
Jun 18, 2026
36 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4634CRITICAL
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient
Sep 6, 20239.888NOYES
CVE-2026-34885HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects
Apr 6, 20268.541NOYES
CVE-2020-11732HIGH
The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.
Apr 13, 20207.537NOYES
CVE-2026-56012HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue
Jun 18, 20268.531NONO
CVE-2020-11928CRITICAL
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
Apr 20, 20209.831NONO
CVE-2026-32399HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL
Mar 13, 20268.527NONO
CVE-2024-6823HIGH
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX actio
Aug 13, 20248.826NONO
CVE-2026-54198HIGH
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
Jun 16, 20267.125NONO
CVE-2024-5605HIGH
The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and i
Jun 20, 20248.825NONO
CVE-2024-51661HIGH
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Com
Nov 4, 20247.224NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
59%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (48.1%)
Unknown0 (0.0%)
Required14 (51.9%)
Privileges Required
Low12 (44.4%)
High4 (14.8%)
None11 (40.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
11.1% of CVEs· 96th percentile
ExploitDB
1 CVE
3.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Davidlingren.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Davidlingren — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Davidlingren's Products

View all 3 CNAs →

Top CWEs