Neliosoftware's vulnerability footprint centers on its Nelio AB Testing plugin, a WordPress-integrated testing and optimization tool, with observed weaknesses clustered around web application input handling and access control. The durable signal reflects server-side request forgery, cross-site request forgery, and path-traversal issues characteristic of web-facing administrative plugins with broad permission scope.
The number and severity of CVEs published that impact products developed by Neliosoftware over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67944CRITICAL Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testin | Jan 22, 2026 | 9.1 | 32 | NO | NO |
CVE-2016-10926CRITICAL The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php. | Aug 22, 2019 | 10.0 | 28 | NO | NO |
CVE-2017-18547HIGH The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms. | Aug 16, 2019 | 8.8 | 26 | NO | NO |
CVE-2016-10927CRITICAL The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php. | Aug 22, 2019 | 10.0 | 25 | NO | NO |
CVE-2026-25378HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.Th | Feb 19, 2026 | 7.6 | 24 | NO | NO |
CVE-2026-40742MEDIUM Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects N | Apr 15, 2026 | 5.3 | 20 | NO | NO |
CVE-2016-10977MEDIUM The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal. | Sep 17, 2019 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neliosoftware.
Media articles that mention a CVE ID that affects a product developed by Neliosoftware — matched by CVE ID, not by vendor name.