Gsplugins develops a collection of WordPress plugins focused on content display and portfolio functionality, including logo sliders, testimonial showcases, and gallery components. The vulnerability profile centers on application-layer input-handling and state-management weaknesses, particularly cross-site scripting and cross-site request forgery issues that are characteristic of web plugin development. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gsplugins over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-30443MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Testimonial Slider allows Stored XSS.This issue affects GS Testi | Mar 29, 2024 | 6.5 | 21 | NO | NO |
CVE-2023-51530HIGH Cross-Site Request Forgery (CSRF) vulnerability in GS Plugins Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.This issue affects Logo Slider – | Feb 29, 2024 | 8.8 | 21 | NO | NO |
CVE-2023-0541MEDIUM The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is | Feb 21, 2023 | 5.4 | 20 | NO | NO |
CVE-2022-4624MEDIUM The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 23, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-0539MEDIUM The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode | Feb 27, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0559MEDIUM The GS Portfolio for Envato WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortco | Feb 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0540MEDIUM The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortco | Feb 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-0492MEDIUM The GS Products Slider for WooCommerce WordPress plugin before 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where | Feb 21, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-40213MEDIUM Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress. | Sep 23, 2022 | 5.4 | 19 | NO | NO |
CVE-2024-30192MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Pins for Pinterest allows Stored XSS.This issue affects GS Pins | Mar 27, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gsplugins.
Media articles that mention a CVE ID that affects a product developed by Gsplugins — matched by CVE ID, not by vendor name.