Mediaburst's vulnerability profile concentrates in WordPress plugins and SMS notification integrations, a modestly represented but notably positioned set of components serving web-form and scheduling workflows. The recurring exposure centers on application-layer input handling, with cross-site scripting and SQL injection weaknesses appearing across products such as Gravity Forms integrations, Clockwork SMS Notifications, and Contact Form 7 plugins, reflecting the parsing and database-query demands of form-processing middleware. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mediaburst over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17780MEDIUM The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found | Dec 20, 2017 | 6.1 | 21 | NO | NO |
CVE-2023-50843HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Clockwork Clockwork SMS Notfications.This issue affects Clockwork SMS Notficat | Dec 28, 2023 | 7.2 | 20 | NO | NO |
CVE-2023-2701MEDIUM The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used a | Jul 17, 2023 | 6.1 | 20 | NO | NO |
CVE-2017-18555MEDIUM The booking-sms plugin before 1.1.0 for WordPress has XSS. | Aug 21, 2019 | 6.1 | 19 | NO | NO |
CVE-2017-18495MEDIUM The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS. | Aug 13, 2019 | 6.1 | 19 | NO | NO |
CVE-2017-18489MEDIUM The contact-form-7-sms-addon plugin before 2.4.0 for WordPress has XSS. | Aug 13, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mediaburst.
Media articles that mention a CVE ID that affects a product developed by Mediaburst — matched by CVE ID, not by vendor name.