Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Infornweb

First CVE: Nov 23, 2021Active for: 5 yearsTotal CVEs: 9

Infornweb develops WordPress plugins focused on content presentation and display functionality, including slider, carousel, and post-listing components that extend site authoring and publishing workflows. These plugins recurrently exhibit serious-outcome vulnerabilities concentrated in web-application input handling and access control, including cross-site scripting, cross-site request forgery, PHP remote file inclusion, and authorization bypass weaknesses that are endemic to WordPress plugin development. Live severity, exploitation activity, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Infornweb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2021
4 years ago
Most Recent CVE
Jun 3, 2025
416 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-5815CRITICAL
The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerab
Nov 22, 20239.841NOYES
CVE-2025-31082HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack blog-designer-pack allo
Apr 1, 20258.122NONO
CVE-2022-4792MEDIUM
The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to
Jan 30, 20235.420NONO
CVE-2022-4749MEDIUM
The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could a
Jan 30, 20235.420NONO
CVE-2021-24729MEDIUM
The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-
Nov 23, 20215.419NONO
CVE-2021-24913MEDIUM
The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_data AJAX action, allowing attackers to make a logged in hig
Feb 28, 20224.318NONO
CVE-2021-24730MEDIUM
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authentica
Feb 28, 20224.318NONO
CVE-2025-4567MEDIUM
The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options before outputting them
Jun 3, 20254.817NONO
CVE-2024-23502MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in InfornWeb Posts List Designer by Category – List Category Posts Or Recent Post
Jan 31, 20245.417NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
11%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low5 (55.6%)
High1 (11.1%)
None3 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Infornweb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Infornweb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Infornweb's Products

View all 3 CNAs →

Top CWEs