Evona's vulnerability footprint centers on a web application product, Per Page Add to Head, with exposure concentrated in application-layer input-handling weaknesses such as cross-site scripting and cross-site request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evona over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24619MEDIUM The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the | Sep 13, 2021 | 4.8 | 18 | NO | NO |
CVE-2021-24586MEDIUM The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthe | Sep 13, 2021 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evona.
Media articles that mention a CVE ID that affects a product developed by Evona — matched by CVE ID, not by vendor name.