Delucks operates a focused SEO tool product that presents a modest vulnerability surface centered on web-application input-handling issues. The recurring exposure involves cross-site scripting and missing authorization flaws, typical for web-facing applications that process and render user-supplied content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Delucks over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48165HIGH Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <= 2.6.0. | Aug 20, 2025 | 8.8 | 28 | NO | NO |
CVE-2024-30538CRITICAL Missing Authorization vulnerability in DELUCKS GmbH DELUCKS SEO.This issue affects DELUCKS SEO: from n/a through 2.5.4. | Jun 9, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-49376HIGH Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects DELUCKS SEO: from n/a thro | Oct 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-53570MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS S | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-54259MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Path Traversal.This issue affects DELUCKS SEO | Dec 13, 2024 | 6.5 | 19 | NO | NO |
CVE-2019-25146MEDIUM The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that had no capability checks in versions up to, and including, 2. | Jun 7, 2023 | 6.1 | 19 | NO | NO |
CVE-2025-47686MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Stored XSS.This issue affects DELUCKS S | May 7, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Delucks.
Media articles that mention a CVE ID that affects a product developed by Delucks — matched by CVE ID, not by vendor name.