Helpful Project maintains a focused web application product where the durable vulnerability signal centers on web-tier issues: improper input handling leading to cross-site scripting and configuration or access-control gaps that expose files or directories to external parties. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Helpful Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2834MEDIUM The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them | Oct 17, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-24841MEDIUM The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even wh | Nov 17, 2021 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Helpful Project.
Media articles that mention a CVE ID that affects a product developed by Helpful Project — matched by CVE ID, not by vendor name.