Joomlaserviceprovider's modest vulnerability footprint centers on web application components such as its JSP Store Locator and WSecure products, where the durable pattern reflects common application-layer input-handling weaknesses including cross-site request forgery, cross-site scripting, SQL injection, and improper input validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joomlaserviceprovider over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10960HIGH The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter. | Sep 16, 2019 | 8.8 | 43 | NO | YES |
CVE-2024-11267HIGH The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL inject | May 15, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-12301MEDIUM The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF a | May 15, 2025 | 6.5 | 18 | NO | NO |
CVE-2023-39987MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions. | Sep 4, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joomlaserviceprovider.
Media articles that mention a CVE ID that affects a product developed by Joomlaserviceprovider — matched by CVE ID, not by vendor name.