Divebook Project maintains a single web-based diving log application that presents a typical attack surface for server-side web platforms, with its vulnerability footprint centered on input-handling and authorization weaknesses including cross-site scripting, SQL injection, and missing authorization controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Divebook Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14206MEDIUM The DiveBook plugin 1.1.4 for WordPress is prone to unauthenticated XSS within the filter function (via an arbitrary parameter). | Dec 8, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-14207MEDIUM The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filte | Dec 8, 2020 | 5.3 | 16 | NO | NO |
CVE-2020-14205MEDIUM The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this iss | Dec 8, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Divebook Project.
Media articles that mention a CVE ID that affects a product developed by Divebook Project — matched by CVE ID, not by vendor name.