Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kieranoshea

First CVE: May 27, 2014Active for: 12 yearsTotal CVEs: 5

Kieranoshea maintains a small portfolio of web-based applications including a calendar and donations platform, with the durable signal centered on application-layer input and request-handling issues such as cross-site scripting, SQL injection, and cross-site request forgery. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kieranoshea over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2014
12 years ago
Most Recent CVE
Dec 23, 2025
216 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-2831HIGH
The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient escaping on the user s
May 2, 20248.824NONO
CVE-2025-14548MEDIUM
The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all versions up to, and including, 1.3.16 due to insufficient input
Dec 23, 20256.422NONO
CVE-2018-18872MEDIUM
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name du
May 13, 20195.419NONO
CVE-2025-13001MEDIUM
The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such as admin to perform SQL i
Dec 2, 20254.118NONO
CVE-2013-2698MEDIUM
Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that ad
May 27, 20146.818NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
80%
20%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (80.0%)
Unknown1 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High0 (0.0%)
Unknown1 (20.0%)
User Interaction
None3 (60.0%)
Unknown1 (20.0%)
Required1 (20.0%)
Privileges Required
Low3 (60.0%)
High1 (20.0%)
None0 (0.0%)
Unknown1 (20.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kieranoshea.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kieranoshea — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kieranoshea's Products

View all 3 CNAs →

Top CWEs