E4jconnect develops a focused line of web-based restaurant and vehicle rental management applications, with its vulnerability footprint concentrated in products such as Vik Rent Car and Vik Restaurants. The recurring exposure centers on application-layer weaknesses including cross-site request forgery, cross-site scripting, SQL injection, and unrestricted file upload, and this vendor's disclosures skew toward serious outcomes. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E4jconnect over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-39653CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-11640HIGH The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or | Mar 8, 2025 | 8.8 | 26 | NO | NO |
CVE-2024-1845HIGH The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwa | Jul 11, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-5322HIGH The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the do_updatecar and createcar funct | Jul 3, 2025 | 7.2 | 22 | NO | NO |
CVE-2025-46251HIGH Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forgery.This issue affects VikRestaurants: from n/a through <= 1 | Apr 22, 2025 | 8.8 | 21 | NO | NO |
CVE-2023-23998MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikRentCar Car Rental Management System plugin <= 1.3.0 versions. | Apr 6, 2023 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E4jconnect.
Media articles that mention a CVE ID that affects a product developed by E4jconnect — matched by CVE ID, not by vendor name.