Dynamiapps maintains a focused administrative frontend product that exhibits a vulnerability profile skewed strongly toward critical-severity outcomes, driven by recurring input-handling and access-control weaknesses including cross-site scripting, SQL injection, improper condition checking, and privilege-management flaws. These weakness classes are typical of web-facing administrative interfaces where input validation gaps and authorization logic can expose sensitive operations to unauthenticated or low-privileged actors. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dynamiapps over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51411CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3 | Dec 29, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-3729CRITICAL The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'fea_encrypt' function in all versions up to, and incl | May 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-11721HIGH The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on th | Dec 14, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-11720MEDIUM The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insuffic | Dec 14, 2024 | 6.1 | 20 | NO | NO |
CVE-2025-26987MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Re | Feb 25, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-11722MEDIUM The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.25.1 due to insufficient es | Dec 21, 2024 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dynamiapps.
Media articles that mention a CVE ID that affects a product developed by Dynamiapps — matched by CVE ID, not by vendor name.