Madfishdigital develops a focused WordPress plugin toolkit for managing search-engine indexation directives, with the observed vulnerability signal centered on cross-site scripting issues in web-facing input handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Madfishdigital over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29791HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Reflected XSS.This iss | Mar 27, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-45065MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <= 1.42 versions. | Oct 18, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-31537HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in madfishdigital Bulk NoIndex & NoFollow Toolkit bulk-noindex-nofollow-toolkit-b | Apr 1, 2025 | 7.1 | 19 | NO | NO |
CVE-2023-41688MEDIUM Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B | Dec 13, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-8803MEDIUM The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL | Sep 26, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Madfishdigital.
Media articles that mention a CVE ID that affects a product developed by Madfishdigital — matched by CVE ID, not by vendor name.