Mearra's vulnerability footprint centers on the AddThis web-sharing widget, a component embedded across numerous third-party websites to facilitate social-media distribution. The durable signal in the vendor's disclosures is cross-site scripting vulnerabilities arising from improper input neutralization during page generation, a class of weakness endemic to client-side content-handling in widely syndicated web components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mearra over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Cross-site scripting (XSS) vulnerability in the AddThis Button module 5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote authenticated users, with administer addthi | Apr 26, 2010 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mearra.
Media articles that mention a CVE ID that affects a product developed by Mearra — matched by CVE ID, not by vendor name.