Mindstien's vulnerability footprint is centered on its My Geo Posts Free product, a modestly scoped web or mapping application with recurring exposure to deserialization of untrusted data. This weakness class reflects input-handling risk common to applications accepting serialized objects from external sources, and defenders should prioritize input validation and deserialization controls when evaluating this vendor's releases. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mindstien over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52433CRITICAL Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a | Nov 18, 2024 | 9.8 | 40 | NO | YES |
CVE-2025-11863MEDIUM The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mygeo_city' shortcode in all versions up to, and including, 1.2. This is due to the | Nov 11, 2025 | 6.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mindstien.
Media articles that mention a CVE ID that affects a product developed by Mindstien — matched by CVE ID, not by vendor name.