Listamester appears to be a modestly scoped platform or service with a focused vulnerability footprint centered on web-related input handling, where the durable signal reflects cross-site scripting weaknesses typical of applications that render user-supplied or third-party content. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Listamester over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30813MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in listamester Listamester listamester allows Stored XSS.This issue affects Lista | Mar 27, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-24678MEDIUM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in listamester Listamester listamester allows Stored XSS.This issue affects Listamester: | Jan 24, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-13659MEDIUM The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due to insuff | Jan 24, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-47446MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in listamester Listamester listamester allows Cross Site Request Forgery.This issue affects Listamester: from n/a through <= 2.3.6. | May 7, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Listamester.
Media articles that mention a CVE ID that affects a product developed by Listamester — matched by CVE ID, not by vendor name.