Mirceatm appears to be the source of a modestly scoped web application, the NMR Strava Activities product, with a focused vulnerability profile centered on client-side input handling. The recurring signal is cross-site scripting, a characteristic weakness in web-facing applications where user input reaches the page output without proper neutralization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mirceatm over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5341MEDIUM The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, 1. | May 8, 2026 | 6.4 | 26 | NO | NO |
CVE-2024-51603MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mirceatm NMR Strava activities nmr-strava-activities allows DOM-Based XSS.This | Nov 9, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mirceatm.
Media articles that mention a CVE ID that affects a product developed by Mirceatm — matched by CVE ID, not by vendor name.