Doofinder is a site search and merchandising platform whose vulnerability disclosures center on its core search product and recur through web-application input-handling and state-management issues, including cross-site scripting, cross-site request forgery, and open-redirect flaws. These weakness classes reflect the attack surface inherent to a customer-facing search interface that processes user input and manages session state. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doofinder over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51697HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder doofinder allows Reflected XSS.This issue affects Doofinde | Nov 9, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-51678MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a through 2.0.33. | Jan 5, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-40602MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Doofinder Doofinder WP & WooCommerce Search.This issue affects Doofinder WP & WooCommerce Search: from n/a thro | Dec 19, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-49185MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder WP & WooCommerce Search allows Reflected XSS.This issue af | Dec 15, 2023 | 6.1 | 17 | NO | NO |
CVE-2024-25596MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder for WooCommerce allows Stored XSS.This issue affects Doofi | Mar 15, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doofinder.
Media articles that mention a CVE ID that affects a product developed by Doofinder — matched by CVE ID, not by vendor name.