Duogeek maintains a small portfolio of WordPress plugins and web utilities, including domain replacement, FAQ, affiliate, and image gallery tools primarily targeting site customization and content management. The observed vulnerability exposure centers on cross-site scripting weaknesses arising from improper input neutralization in web-page generation contexts, a pattern typical of plugins handling user-supplied content or configuration data. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Duogeek over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39319MEDIUM The duoFAQ - Responsive, Flat, Simple FAQ WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/duogeek/duogeek-panel.php file which | Dec 14, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-39313MEDIUM The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers | Dec 14, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-2077MEDIUM The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 due to insuffic | Mar 12, 2025 | 6.1 | 18 | NO | NO |
CVE-2022-1218MEDIUM The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross- | May 23, 2022 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Duogeek.
Media articles that mention a CVE ID that affects a product developed by Duogeek — matched by CVE ID, not by vendor name.