Digitialpixies develops an OAuth client product where vulnerabilities center on web-application input-handling and request-validation issues, including cross-site scripting and cross-site request forgery. These weakness classes are characteristic of client-side authentication integrations and reflect the complexity of safely mediating user input and session state in OAuth flows. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digitialpixies over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3632MEDIUM The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted act | Nov 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-3631MEDIUM The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perfor | Nov 14, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digitialpixies.
Media articles that mention a CVE ID that affects a product developed by Digitialpixies — matched by CVE ID, not by vendor name.