Imagerecycle operates a focused product line centered on PDF and image compression utilities that attract a more prominent position in the vulnerability landscape than typical for a niche software vendor. Its vulnerability disclosures recur around web-application input and access-control boundaries—cross-site request forgery, missing authorization checks, and cross-site scripting—consistent with a compression service exposed as a web interface or embedded in web applications. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imagerecycle over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40196MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.11 versions. | Sep 4, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-30494MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ImageRecycle ImageRecycle pdf & image compression plugin <= 3.1.10 versions. | Sep 4, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-54266MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression imagerecycle-pdf-image-compr | Dec 13, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8120MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or in | Aug 24, 2024 | 4.3 | 17 | NO | NO |
CVE-2024-6631MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all ve | Aug 24, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-1339MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or in | Feb 29, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-1335MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or in | Feb 29, 2024 | 4.3 | 16 | NO | NO |
CVE-2024-1336MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or in | Feb 29, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-1334MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or in | Feb 29, 2024 | 4.3 | 15 | NO | NO |
CVE-2024-1090MEDIUM The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function i | Feb 29, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imagerecycle.
Media articles that mention a CVE ID that affects a product developed by Imagerecycle — matched by CVE ID, not by vendor name.