Davidlingren's vulnerability footprint centers on a single media-management application and skews toward serious outcomes, with vulnerabilities frequently acquiring public exploit code. The recurring weakness classes—cross-site scripting, SQL injection, sensitive information exposure, and file-path manipulation—reflect common input-handling and access-control gaps in web-facing media-library software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Davidlingren over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4634CRITICAL The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient | Sep 6, 2023 | 9.8 | 88 | NO | YES |
CVE-2026-34885HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects | Apr 6, 2026 | 8.5 | 41 | NO | YES |
CVE-2020-11732HIGH The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download. | Apr 13, 2020 | 7.5 | 37 | NO | YES |
CVE-2026-56012HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection.
This issue | Jun 18, 2026 | 8.5 | 31 | NO | NO |
CVE-2020-11928CRITICAL In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin. | Apr 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-32399HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL | Mar 13, 2026 | 8.5 | 27 | NO | NO |
CVE-2024-6823HIGH The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX actio | Aug 13, 2024 | 8.8 | 26 | NO | NO |
CVE-2026-54198HIGH Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions. | Jun 16, 2026 | 7.1 | 25 | NO | NO |
CVE-2024-5605HIGH The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and i | Jun 20, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-51661HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Com | Nov 4, 2024 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Davidlingren.
Media articles that mention a CVE ID that affects a product developed by Davidlingren — matched by CVE ID, not by vendor name.