Getlasso's vulnerability profile centers on its Simple URLs product, a web-based URL-shortening or redirection utility that handles user-supplied inputs and request routing. The durable signal reflects application-layer exposure to cross-site scripting and cross-site request forgery, which are endemic to web services that process and render user data without sufficient input sanitization or token validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getlasso over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0099MEDIUM The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which | Feb 13, 2023 | 6.1 | 25 | NO | YES |
CVE-2023-0098HIGH The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, l | Feb 13, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-45606HIGH Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions. | Oct 16, 2023 | 8.8 | 21 | NO | NO |
CVE-2023-40667MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions. | Sep 27, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-40674MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Manage | Nov 30, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getlasso.
Media articles that mention a CVE ID that affects a product developed by Getlasso — matched by CVE ID, not by vendor name.