Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nicdark

First CVE: Mar 7, 2022Active for: 4 yearsTotal CVEs: 13
18.7
VTI Score
Low

Nicdark develops a focused line of WordPress plugins and extensions centered on travel, hospitality, and booking functionality, including cost calculators, shortcode systems, and hotel and travel reservation tools. The recurring vulnerability signal across this portfolio centers on cross-site scripting weaknesses arising from improper input neutralization in web page generation, a pattern typical of plugin-based content management layers. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nicdark over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2022
4 years ago
Most Recent CVE
Dec 31, 2025
205 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1273HIGH
The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticat
Jul 4, 20238.827NONO
CVE-2025-39526HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Incl
Apr 17, 20258.122NONO
CVE-2025-63001MEDIUM
Missing Authorization vulnerability in nicdark Hotel Booking nd-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hotel Booking: fr
Dec 31, 20255.320NONO
CVE-2025-53259HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Incl
Jun 27, 20257.520NONO
CVE-2025-47498HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Incl
May 7, 20257.520NONO
CVE-2022-4623MEDIUM
The ND Shortcodes WordPress plugin before 7.0 does not validate and escape numerous of its shortcode attributes before outputting them back in a page/post where the shortcode is em
Jul 4, 20235.420NONO
CVE-2021-24821MEDIUM
The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the Description fields of a Cost C
Mar 7, 20225.420NONO
CVE-2023-1155MEDIUM
The Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the nd_cc_meta_box_cc_price_icon parameter in versions up to, and including, 1.8 due to in
Mar 2, 20235.419NONO
CVE-2022-29443MEDIUM
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.
Jun 15, 20225.419NONO
CVE-2022-27859MEDIUM
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin <= 2.0 at WordPress.
Jun 15, 20225.419NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
69%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High3 (23.1%)
Unknown0 (0.0%)
User Interaction
None5 (38.5%)
Unknown0 (0.0%)
Required8 (61.5%)
Privileges Required
Low11 (84.6%)
High0 (0.0%)
None2 (15.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nicdark.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nicdark — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nicdark's Products

View all 3 CNAs →

Top CWEs