Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Joomunited

First CVE: Aug 20, 2019Active for: 7 yearsTotal CVEs: 29
20.7
VTI Score
Low

Joomunited develops a focused suite of WordPress plugins and extensions that extend content management and data-handling capabilities, achieving prominence despite a narrowly scoped product portfolio. The vendor's vulnerability exposure recurs across plugins such as WP Meta SEO, WP Table Manager, WP Smart Editor, WP File Download, and WP Latest Posts through weakness classes centered on web application security primitives: cross-site scripting, missing authorization, cross-site request forgery, unsafe deserialization, and metadata exposure. These flaws reflect the challenges of building extensible WordPress components that interact with user input, administrative functions, and sensitive data while respecting WordPress's permission model. The exposure profile shows a moderate tendency toward serious-severity outcomes and a low tendency toward public exploit availability, while defenders should prioritize patching exposed WordPress installations running these plugins and ensure strict access controls on administrative functions. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Joomunited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2019
6 years ago
Most Recent CVE
Jun 24, 2026
31 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-9643HIGH
The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18.
Jun 24, 20267.232NONO
CVE-2026-9620MEDIUM
The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0.11. Thi
Jun 24, 20266.430NONO
CVE-2026-11370MEDIUM
The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible
Jun 24, 20266.430NONO
CVE-2023-0876MEDIUM
The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redi
Mar 20, 20236.130NOYES
CVE-2023-0875HIGH
The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnerability that can be exploited by
Mar 20, 20238.828NONO
CVE-2023-1381HIGH
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. F
Apr 10, 20238.827NONO
CVE-2024-25909HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.
Feb 26, 20248.824NONO
CVE-2023-6961MEDIUM
The WP Meta SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Referer’ header in all versions up to, and including, 4.5.12 due to insufficient input sa
May 2, 20246.121NONO
CVE-2025-5034HIGH
The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Jun 21, 20257.120NONO
CVE-2024-13374MEDIUM
The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and includ
Feb 12, 20256.520NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
83%
17%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network29 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (58.6%)
Unknown0 (0.0%)
Required12 (41.4%)
Privileges Required
Low16 (55.2%)
High2 (6.9%)
None11 (37.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.4% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Joomunited.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Joomunited — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Joomunited's Products

View all 4 CNAs →

Top CWEs