Donorbox is a web-based donation and fundraising platform whose vulnerability footprint centers on cross-site scripting weaknesses in its web application layer, reflecting the input-handling demands of a browser-based payment-collection service. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Donorbox over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1396MEDIUM The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting iss | Apr 25, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Donorbox.
Media articles that mention a CVE ID that affects a product developed by Donorbox — matched by CVE ID, not by vendor name.