Lenderd's vulnerability footprint centers on mortgage-related web applications, including its 1003 Mortgage Application and WordPress-based mortgage calculators, with an observed pattern of input-handling weaknesses. The recurring issues involve improper neutralization of formula elements in CSV exports and cross-site scripting in web page generation, reflecting risks endemic to forms and data-processing layers in financial web tools.
The number and severity of CVEs published that impact products developed by Lenderd over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24904MEDIUM The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privileg | Feb 14, 2022 | 4.8 | 30 | NO | YES |
CVE-2022-45357CRITICAL Improper Neutralization of Formula Elements in a CSV File vulnerability in Lenderd 1003 Mortgage Application.This issue affects 1003 Mortgage Application: from n/a through 1.75. | Nov 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-45368HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Lenderd 1003 Mortgage Application allows Relative Path Traversal.This issue affects | May 17, 2024 | 7.7 | 22 | NO | NO |
CVE-2024-32581MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lenderd Mortgage Calculators WP allows Stored XSS.This issue affects Mortgage | Apr 18, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lenderd.
Media articles that mention a CVE ID that affects a product developed by Lenderd — matched by CVE ID, not by vendor name.