Gdprinfo develops a web-focused plugin for embedding GDPR and CCPA compliance notices on websites, presenting a modest attack surface centered on a single product offering. The observed vulnerability signal concentrates on cross-site scripting weaknesses in the banner and consent-generation logic, a characteristic risk for client-side compliance tools that process and render user-configurable content. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gdprinfo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58607MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-not | Sep 3, 2025 | 6.5 | 21 | NO | NO |
CVE-2021-24590MEDIUM The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plug | Sep 6, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gdprinfo.
Media articles that mention a CVE ID that affects a product developed by Gdprinfo — matched by CVE ID, not by vendor name.