Ladipage is a web-based landing page builder and website creation platform whose vulnerability profile centers on input-handling and access-control gaps typical of application-facing web services. The recurring weakness classes—cross-site request forgery, missing authorization checks, and cross-site scripting—reflect the challenges of securing user-generated content and session management in a multi-tenant SaaS environment. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ladipage over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4728MEDIUM The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an AJAX action in vers | Mar 12, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-4731MEDIUM The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in versions up to, and in | Mar 12, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-4729MEDIUM The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX action in versions up to, | Mar 12, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-4629MEDIUM The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, and including, 4.3. This | Mar 12, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-4628MEDIUM The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, and including, 4.4 | Mar 12, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-4627MEDIUM The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up to, and including | Mar 12, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-4626MEDIUM The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and in | Mar 12, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ladipage.
Media articles that mention a CVE ID that affects a product developed by Ladipage — matched by CVE ID, not by vendor name.