The Donations Project maintains a web-based donations platform whose vulnerability profile centers on web-application input-handling weaknesses including cross-site scripting, SQL injection, and open redirects. These are characteristic risks in user-facing donation collection systems where input validation and output encoding maturity directly govern both data integrity and user trust. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Donations Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0782CRITICAL The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_vali | Apr 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-29433MEDIUM Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress. | May 13, 2022 | 5.4 | 20 | NO | NO |
CVE-2019-15772MEDIUM The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. | Aug 29, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Donations Project.
Media articles that mention a CVE ID that affects a product developed by Donations Project — matched by CVE ID, not by vendor name.