Ovation offers WordPress plugins and web content management extensions, including Dynamic Content and FindMe, that handle user input and page generation in web publishing workflows. The recurring vulnerability signal centers on web-application input-handling and output-encoding flaws, particularly cross-site request forgery, improper input validation, and cross-site scripting weaknesses that are characteristic of plugin-based content systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ovation over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15885HIGH Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the produ | Aug 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2023-52150HIGH Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5. | Jan 5, 2024 | 8.8 | 23 | NO | NO |
CVE-2021-3327MEDIUM Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. | Mar 19, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ovation.
Media articles that mention a CVE ID that affects a product developed by Ovation — matched by CVE ID, not by vendor name.