Emarketdesign's vulnerability profile centers on a modest portfolio of web-based business and event-management applications, including request-quoting, customer-service ticketing, and video-gallery features. The recurring weakness classes—cross-site scripting, cross-site request forgery, formula injection in CSV exports, and missing authorization controls—reflect the input-handling and access-control challenges endemic to web applications that process user-supplied data and manage multi-tenant or role-based workflows. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emarketdesign over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2240HIGH The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead | Jul 25, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-53572HIGH Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injection.This issue affects WP Easy Contact: from n/a through <= 4. | Aug 28, 2025 | 8.1 | 26 | NO | NO |
CVE-2023-40558HIGH Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions. | Oct 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-58915MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Request a Quote request-a-quote allows Stored XSS.This issue af | Sep 23, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-5539MEDIUM The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all ver | Jun 4, 2025 | 6.4 | 19 | NO | NO |
CVE-2022-2239MEDIUM The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting att | Jul 25, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-2151MEDIUM The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scr | Jul 17, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-24489MEDIUM The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scri | Oct 25, 2021 | 4.8 | 19 | NO | NO |
CVE-2021-24420MEDIUM The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting | Jul 12, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-6231MEDIUM The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Si | Jul 23, 2024 | 5.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emarketdesign.
Media articles that mention a CVE ID that affects a product developed by Emarketdesign — matched by CVE ID, not by vendor name.