External Media Project maintains a narrowly scoped media-handling library or tool where the recurring vulnerability signal centers on unrestricted file upload mechanisms that can accept dangerous file types. This reflects the inherent challenge of validating and constraining user-supplied media content in a way that prevents subsequent exploitation. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by External Media Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24311HIGH The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any authenticated users. | Jun 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-3832MEDIUM The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Si | Dec 19, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by External Media Project.
Media articles that mention a CVE ID that affects a product developed by External Media Project — matched by CVE ID, not by vendor name.