The Gd Rating System Project maintains a focused, single-product vulnerability profile centered on its rating system application, which sees use across web environments where user-generated content and input handling carry inherent risk. The recurring weaknesses—path traversal and cross-site scripting—reflect the common challenges of web application input validation and file-access control in systems that process untrusted user submissions. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gd Rating System Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5291HIGH The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page. | Jan 8, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-5290HIGH The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page. | Jan 8, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-5289HIGH The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page. | Jan 8, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-5287HIGH The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page. | Jan 8, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-5288MEDIUM The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page. | Jan 8, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-5293MEDIUM The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page. | Jan 8, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-5292MEDIUM The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page. | Jan 8, 2018 | 6.1 | 20 | NO | NO |
CVE-2018-5286MEDIUM The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page. | Jan 8, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gd Rating System Project.
Media articles that mention a CVE ID that affects a product developed by Gd Rating System Project — matched by CVE ID, not by vendor name.