Geminilabs' vulnerability profile centers on its Site Reviews product, a web-based review management application, where disclosures skew toward serious outcomes and frequently acquire public exploit code. The recurring weakness classes—cross-site scripting, CSV formula injection, and related input-handling flaws—reflect the application's role in processing and rendering user-supplied review content across web interfaces. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geminilabs over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1232HIGH The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attack | Mar 19, 2025 | 8.8 | 40 | NO | YES |
CVE-2026-57318MEDIUM Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. | Jun 26, 2026 | 6.5 | 29 | NO | NO |
CVE-2022-46801CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in Paul Ryley Site Reviews.This issue affects Site Reviews: from n/a through 6.2.0. | Nov 7, 2023 | 9.8 | 25 | NO | NO |
CVE-2024-3050CRITICAL The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to b | May 29, 2024 | 9.1 | 24 | NO | NO |
CVE-2018-0603MEDIUM Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jun 26, 2018 | 6.1 | 22 | NO | NO |
CVE-2021-24973MEDIUM The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authent | Jan 3, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-24603MEDIUM The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scriptin | Sep 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2024-29095MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gemini Labs Site Reviews site-reviews.This issue affects Site Reviews: from n/ | Mar 19, 2024 | 5.9 | 18 | NO | NO |
CVE-2024-2293MEDIUM The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all versions up to, and including, 6.11.4 due to insufficient input | Mar 13, 2024 | 6.4 | 18 | NO | NO |
CVE-2023-1525MEDIUM The Site Reviews WordPress plugin before 6.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | May 2, 2023 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geminilabs.
Media articles that mention a CVE ID that affects a product developed by Geminilabs — matched by CVE ID, not by vendor name.