Mediavine operates a modestly represented portfolio centered on its Create and Control Panel products that serve content creators and publishers, with the observed vulnerability exposure clustering around web application input handling and session management. The recurring weakness classes—cross-site scripting, cross-site request forgery, and sensitive information leakage—reflect the authentication and data-handling demands of web-based creator and publishing platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mediavine over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44259HIGH Cross-Site Request Forgery (CSRF) vulnerability in Mediavine Mediavine Control Panel plugin <= 2.10.2 versions. | Oct 10, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-25424MEDIUM Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | Jul 23, 2026 | 4.3 | 22 | NO | NO |
CVE-2024-43264HIGH Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create by Mediavine: from n/a through <= 1 | Aug 26, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-43218MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mediavine Mediavine Control Panel mediavine-control-panel.This issue affects M | Aug 12, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-5601MEDIUM The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta shortcode in all versions up to, and including, 1.9.7 due to | Jun 27, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-37495MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mischiefmarmot Create by Mediavine mediavine-create.This issue affects Create | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-39556MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensi | Apr 16, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mediavine.
Media articles that mention a CVE ID that affects a product developed by Mediavine — matched by CVE ID, not by vendor name.