Landing Pages Project maintains a web-based landing page creation and hosting platform, with a modestly represented vulnerability footprint concentrated in the core product and its plugin ecosystem. The durable signal centers on application-layer input-handling weaknesses, specifically SQL injection and cross-site scripting, which are characteristic of web-facing content-management and form-processing systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Landing Pages Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4064MEDIUM SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL comma | May 27, 2015 | 6.5 | 27 | NO | YES |
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inj | May 27, 2015 | 3.5 | 20 | NO | YES |
CVE-2013-6243HIGH SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" p | Oct 23, 2013 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Landing Pages Project.
Media articles that mention a CVE ID that affects a product developed by Landing Pages Project — matched by CVE ID, not by vendor name.