Piwebsolution develops a focused portfolio of e-commerce plugins for the WooCommerce platform, including product inquiry, checkout, shipping, and order-management extensions that directly handle customer data and transaction workflows. Its vulnerabilities concentrate in application-layer input-handling and state-management issues, with recurring exposure to cross-site scripting, cross-site request forgery, and untrusted deserialization that reflect the web-facing and form-processing nature of these plugins. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Piwebsolution over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59512HIGH Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | Jul 23, 2026 | 7.1 | 29 | NO | NO |
CVE-2022-47154HIGH Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | Mar 14, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-8922HIGH The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via dese | Sep 27, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-34015HIGH Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1. | Jul 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-3603CRITICAL The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CS | Nov 28, 2022 | 9.8 | 24 | NO | NO |
CVE-2023-29094MEDIUM Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <= 1.3.20 versions. | Apr 7, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-29093MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PI Websolution Conditional cart fee plugin <= 1.0.96 versions. | Jun 26, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-28991MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date time, Pickup Location, delivery date for WooCommerce plugin <= | Jun 26, 2023 | 4.8 | 17 | NO | NO |
CVE-2023-29423MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versio | Jun 26, 2023 | 4.8 | 16 | NO | NO |
CVE-2023-28988MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Direct checkout, Add to cart redirect, Quick purchase button, Buy now button, Quick View button for | Jun 26, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Piwebsolution.
Media articles that mention a CVE ID that affects a product developed by Piwebsolution — matched by CVE ID, not by vendor name.