If Me is a mental-health and wellness-focused digital platform with a narrow product scope centered on its primary application. The vendor's limited disclosure history reflects the specialized nature of the platform rather than a broad infrastructure or high-volume software footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by If Me over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25992CRITICAL In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies | Feb 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-25991HIGH In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme ac | Dec 29, 2021 | 7.3 | 24 | NO | NO |
CVE-2021-25990MEDIUM In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe. | Dec 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-25989MEDIUM In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which trigge | Dec 29, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-25988MEDIUM In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin | Dec 29, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by If Me.
Media articles that mention a CVE ID that affects a product developed by If Me — matched by CVE ID, not by vendor name.