Donweb is a hosting and domain services provider whose vulnerability profile centers on its email and messaging platform, EnviaLoSimple. The observed weakness classes span cross-site request forgery, deserialization of untrusted data, and unrestricted file uploads—input-handling and session-management issues characteristic of web-facing communication applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Donweb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51414CRITICAL Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from | Dec 29, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-2125HIGH The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing | Apr 9, 2024 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Donweb.
Media articles that mention a CVE ID that affects a product developed by Donweb — matched by CVE ID, not by vendor name.