Infoway maintains a small portfolio of consumer-facing applications including an ebook downloader and social photo gallery, both vulnerable to application-layer input-handling defects. The recurring exposure pattern centers on SQL injection and improper file-upload validation, typical of web-accessible software lacking robust input sanitization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infoway over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14467HIGH The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file ex | Nov 18, 2019 | 7.8 | 25 | NO | NO |
CVE-2024-13435HIGH The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up to, and including, 1.0 due to insufficient escaping on the | Feb 12, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infoway.
Media articles that mention a CVE ID that affects a product developed by Infoway — matched by CVE ID, not by vendor name.