Deepsoft operates a narrowly scoped portfolio centered on its WebLibrarian product, a web-based application where the durable signal points to application-layer input-handling vulnerabilities. The observed weakness classes—cross-site scripting and SQL injection—reflect recurring gaps in input neutralization and parameterization typical of web applications handling untrusted user data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deepsoft over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29441MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions. | Sep 6, 2023 | 6.1 | 22 | NO | NO |
CVE-2019-1010034MEDIUM Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at d | Jul 15, 2019 | 6.5 | 22 | NO | NO |
CVE-2017-18540MEDIUM The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes. | Aug 21, 2019 | 6.1 | 20 | NO | NO |
CVE-2017-18539MEDIUM The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes. | Aug 21, 2019 | 6.1 | 20 | NO | NO |
CVE-2017-18538MEDIUM The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes. | Aug 21, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deepsoft.
Media articles that mention a CVE ID that affects a product developed by Deepsoft — matched by CVE ID, not by vendor name.