Graphpaperpress maintains a focused portfolio of WordPress-oriented plugins and themes, including Sell Media and F8 Lite, that extend e-commerce and content-management capabilities on self-hosted sites. The vulnerability signals center on application-layer input-handling issues characteristic of web plugins, specifically cross-site scripting and cross-site request forgery weaknesses arising from insufficient output encoding and state validation in form processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphpaperpress over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6112MEDIUM A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via | Aug 14, 2020 | 6.1 | 36 | NO | YES |
CVE-2011-3855MEDIUM Cross-site scripting (XSS) vulnerability in the F8 Lite theme before 4.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | Sep 28, 2011 | 4.3 | 26 | NO | YES |
CVE-2021-4420MEDIUM The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the | Jul 12, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphpaperpress.
Media articles that mention a CVE ID that affects a product developed by Graphpaperpress — matched by CVE ID, not by vendor name.