Marcomilesi's vulnerability profile centers on a narrow line of web-facing tools and WordPress-related components, including attachment handlers, XML viewers for Italian public procurement data, and browser themes. The recurring weakness classes—cross-site scripting and cross-site request forgery—reflect the vendor's focus on client-side and form-handling contexts where input neutralization and session protection are critical. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marcomilesi over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22291HIGH Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3. | Jan 31, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-45651HIGH Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11. | Oct 16, 2023 | 8.8 | 23 | NO | NO |
CVE-2025-62888MEDIUM Missing Authorization vulnerability in Marco Milesi WP Attachments wp-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Atta | Dec 31, 2025 | 5.4 | 19 | NO | NO |
CVE-2023-47656MEDIUM Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions. | Nov 14, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-4330MEDIUM The WP Attachments WordPress plugin before 5.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit | Jan 16, 2023 | 4.8 | 19 | NO | NO |
CVE-2022-3469MEDIUM The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Si | Nov 14, 2022 | 4.8 | 19 | NO | NO |
CVE-2023-47242MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions. | Nov 16, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-47245MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Viewer plugin <= 1.7 versions. | Nov 16, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marcomilesi.
Media articles that mention a CVE ID that affects a product developed by Marcomilesi — matched by CVE ID, not by vendor name.