Gistpress Project develops a WordPress plugin focused on embedding GitHub Gist content within pages, presenting a narrowly scoped web-application attack surface. The observed vulnerability pattern centers on cross-site scripting issues arising from improper neutralization of user-supplied input during page generation, a common class for content-embedding and output-rendering plugins. Current exposure counts and severity metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gistpress Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8498MEDIUM XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the Wor | Jan 30, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gistpress Project.
Media articles that mention a CVE ID that affects a product developed by Gistpress Project — matched by CVE ID, not by vendor name.