Logicore's vulnerability footprint concentrates in its Pocket News Generator web application, with the observed weakness classes centered on web-facing input-handling and request-validation issues, specifically cross-site scripting and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Logicore over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2963MEDIUM The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "Consumer Key" and "Access Token" in all versions up to, and | Mar 29, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-2964MEDIUM The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.0. This is due to missing or incorrect nonce va | Mar 29, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Logicore.
Media articles that mention a CVE ID that affects a product developed by Logicore — matched by CVE ID, not by vendor name.