Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Implecode

First CVE: Nov 23, 2021Active for: 5 yearsTotal CVEs: 22
26.8
VTI Score
Low

Implecode develops e-commerce product catalog and review management plugins that integrate with web-based shopping platforms, with vulnerabilities clustering around web application input handling and session management. The recurring weakness classes center on cross-site scripting, cross-site request forgery, and improper input validation—typical exposures for web-facing catalog and user-interaction components—alongside occasional information-disclosure risks. Defenders managing Implecode-based storefronts should prioritize input sanitization and CSRF protection in plugin deployments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 28% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Implecode over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2021
4 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-52693CRITICAL
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
Jun 15, 20269.334NONO
CVE-2021-24875MEDIUM
The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, lead
Nov 23, 20216.130NOYES
CVE-2026-57360HIGH
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
Jul 2, 20267.129NONO
CVE-2021-24894MEDIUM
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the review section when
Nov 23, 20216.523NONO
CVE-2025-58992MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affe
Sep 22, 20256.522NONO
CVE-2023-51687HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode Product Catalog Simple.This issue affects Product Catalog Simple: from n/a through 1.7.6.
Dec 29, 20237.521NONO
CVE-2023-29388MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions.
Apr 7, 20236.121NONO
CVE-2025-49331HIGH
Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue affects eCommerce Product Catalo
Jun 17, 20257.220NONO
CVE-2024-32558HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eC
Apr 18, 20247.119NONO
CVE-2023-51688HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Pl
Dec 29, 20237.519NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
73%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (27.3%)
Unknown0 (0.0%)
Required16 (72.7%)
Privileges Required
Low6 (27.3%)
High3 (13.6%)
None13 (59.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.5% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Implecode.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Implecode — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Implecode's Products

View all 3 CNAs →

Top CWEs