Imdpen's vulnerability footprint centers on video-conferencing integration, particularly around products and services interacting with Zoom, where disclosures cluster around information exposure, cross-site scripting, and cryptographic key management weaknesses. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imdpen over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0384MEDIUM The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscr | Mar 7, 2022 | 4.3 | 19 | NO | NO |
CVE-2023-3947MEDIUM The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in ve | Jul 26, 2023 | 5.3 | 17 | NO | NO |
CVE-2024-2031MEDIUM The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, an | Mar 12, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imdpen.
Media articles that mention a CVE ID that affects a product developed by Imdpen — matched by CVE ID, not by vendor name.