Optiontree Project maintains a focused web application framework product where vulnerabilities cluster around deserialization of untrusted data and cross-site scripting, reflecting the risks inherent to dynamic code execution and HTML generation in application frameworks. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Optiontree Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15319CRITICAL The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. | Aug 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-15320CRITICAL The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. | Aug 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15321CRITICAL The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. | Aug 22, 2019 | 9.8 | 28 | NO | NO |
CVE-2015-9320MEDIUM The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg. | Aug 20, 2019 | 6.1 | 21 | NO | NO |
CVE-2016-10895MEDIUM The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request. | Aug 20, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Optiontree Project.
Media articles that mention a CVE ID that affects a product developed by Optiontree Project — matched by CVE ID, not by vendor name.