Highfivery develops a focused line of email security and spam-filtering products, including the Zero-Spam suite for WordPress and general messaging platforms. The recurring vulnerability signal centers on SQL injection risks in these web-application components, reflecting input-handling patterns common to database-backed filtering systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Highfivery over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0254CRITICAL The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dash | Mar 14, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-32121HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects | Nov 3, 2023 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Highfivery.
Media articles that mention a CVE ID that affects a product developed by Highfivery — matched by CVE ID, not by vendor name.