Four Kitchens develops web application and content-management components, with observed vulnerability exposure centered on its Block Class product and input-handling issues such as cross-site scripting in web page generation contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Four Kitchens over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3144MEDIUM Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permissio | Apr 15, 2016 | 5.4 | 20 | NO | NO |
CVE-2025-3902MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block | Apr 23, 2025 | 6.1 | 18 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Read More Link module 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users with the access administration pages permi | Sep 18, 2012 | 2.1 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inj | Sep 18, 2012 | 2.1 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary | Mar 25, 2010 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Four Kitchens.
Media articles that mention a CVE ID that affects a product developed by Four Kitchens — matched by CVE ID, not by vendor name.