Dublue's vulnerability profile centers on its Table of Contents Plus product, a web-based application where disclosures cluster around client-side input-handling issues including cross-site request forgery and cross-site scripting. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dublue over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49250HIGH Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Table of Contents Plus table-of-contents-plus allows Cross Site Request Forgery.This issue affects Table of Contents | Oct 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-44473HIGH Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus plugin <= 2302 versions. | Oct 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-4479MEDIUM The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow use | Jan 9, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-5578MEDIUM The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross- | Nov 5, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dublue.
Media articles that mention a CVE ID that affects a product developed by Dublue — matched by CVE ID, not by vendor name.