Howardehrenberg maintains a narrowly focused WordPress plugin product (Custom Post Carousels with Owl) whose vulnerability pattern reflects typical web-application input-handling risk, centered on cross-site scripting weaknesses in page-generation logic. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Howardehrenberg over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51493MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Custom Post Carousels with Owl allows Stored XSS.This issue a | Feb 10, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-5125MEDIUM The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it. | Jun 20, 2025 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Howardehrenberg.
Media articles that mention a CVE ID that affects a product developed by Howardehrenberg — matched by CVE ID, not by vendor name.