The Imagestowebp Project maintains a utility for converting images to the WebP format, a niche application with a focused vulnerability footprint centered on web-interaction and file-handling mechanisms. Observed weakness classes include cross-site request forgery and path-traversal conditions, reflecting risks inherent to tools that process user-supplied file inputs and expose web-based conversion interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imagestowebp Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24644HIGH The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusi | Nov 23, 2021 | 7.5 | 36 | NO | YES |
CVE-2021-24641HIGH The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings | Nov 23, 2021 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imagestowebp Project.
Media articles that mention a CVE ID that affects a product developed by Imagestowebp Project — matched by CVE ID, not by vendor name.