Masuga Design's vulnerability profile centers on a niche WordPress plugin, the Unobtrusive AJAX Star Rating Bar, used for user-facing content rating functionality. The disclosed weaknesses reflect common plugin-tier input and access-control patterns; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Masuga Design over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3684HIGH Multiple SQL injection vulnerabilities in Unobtrusive Ajax Star Rating Bar before 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) q and (2) t parameters | Jul 11, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-3686HIGH CRLF injection vulnerability in db.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary HTTP headers and data via CRLF sequences in the | Jul 11, 2007 | 7.5 | 19 | NO | NO |
Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the q parame | Jul 11, 2007 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Masuga Design.
Media articles that mention a CVE ID that affects a product developed by Masuga Design — matched by CVE ID, not by vendor name.