Frenify maintains a focused portfolio of web-facing applications, including Categorify and Mediamatic, that serve as categorization and media-management tools with notable deployment reach in their respective verticals. The recurring vulnerability signal centers on application-layer flaws including cross-site request forgery, missing authorization checks, and SQL injection—weaknesses typical of web applications where input handling and access control are critical. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frenify over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24848HIGH The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before | Dec 13, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-47144HIGH Cross-Site Request Forgery (CSRF) vulnerability in Plugincraft Mediamatic – Media Library Folders plugin <= 2.8.1 versions. | May 25, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-0294MEDIUM The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.1. This is due to missing or incorrect | Jan 13, 2023 | 4.3 | 18 | NO | NO |
CVE-2025-59005MEDIUM Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Categorify: from n/a | Sep 9, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-1650MEDIUM The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all version | Feb 27, 2024 | 4.3 | 17 | NO | NO |
CVE-2024-1910MEDIUM The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation | Feb 27, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-1906MEDIUM The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation | Feb 27, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-0385MEDIUM The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxAddCategory function in all versions u | Mar 13, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-1912MEDIUM The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation | Feb 27, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-1909MEDIUM The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation | Feb 27, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frenify.
Media articles that mention a CVE ID that affects a product developed by Frenify — matched by CVE ID, not by vendor name.