Freehtmldesigns' vulnerability footprint centers on a web-application product with a pattern of web-tier implementation issues, including authorization bypass through user-controlled keys, cross-site request forgery, and cross-site scripting. Current exploitation activity, exposure counts, and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freehtmldesigns over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35773HIGH The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF. | Dec 29, 2020 | 8.8 | 27 | NO | NO |
CVE-2022-1580MEDIUM The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. | Sep 19, 2022 | 4.3 | 21 | NO | YES |
CVE-2023-49190MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows St | Dec 15, 2023 | 4.8 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freehtmldesigns.
Media articles that mention a CVE ID that affects a product developed by Freehtmldesigns — matched by CVE ID, not by vendor name.