Idxbroker offers web-based real estate search and listing management solutions, with its vulnerability profile concentrated in the Impress for Idxbroker product line. The durable signal reflects application-layer input handling and authorization weaknesses, including cross-site scripting and missing authorization controls common to web-facing property management platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Idxbroker over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9514MEDIUM An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in user (with the Subscriber role) to permanently delete arbit | Apr 7, 2020 | 6.5 | 22 | NO | NO |
CVE-2025-31556MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress for IDX Broker idx-broker-platinum allows Stored XSS.This i | Mar 31, 2025 | 6.5 | 17 | NO | NO |
CVE-2024-44047MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IDX Broker IMPress for IDX Broker idx-broker-platinum allows Stored XSS.This i | Sep 17, 2024 | 5.4 | 16 | NO | NO |
CVE-2020-11512MEDIUM Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subscriber-level) permissions to save arbitrary JavaScript in th | Apr 7, 2020 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Idxbroker.
Media articles that mention a CVE ID that affects a product developed by Idxbroker — matched by CVE ID, not by vendor name.