Krishaweb develops WordPress plugins such as Add Multiple Marker and Contact Form 7 Email Add-on, where vulnerabilities center on web-application input handling and request validation issues including cross-site request forgery and PHP remote file inclusion. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Krishaweb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45080HIGH Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions. | Apr 23, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-10898HIGH The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_email_add_on_add_admin_template() f | Nov 21, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Krishaweb.
Media articles that mention a CVE ID that affects a product developed by Krishaweb — matched by CVE ID, not by vendor name.