Pixelimity maintains a focused web application product with a durable vulnerability profile centered on input-handling and request-validation weaknesses such as cross-site scripting, SQL injection, cross-site request forgery, and downstream injection flaws that are characteristic of web-application attack surfaces. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, reflecting the accessibility and straightforward nature of these weakness classes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixelimity over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28590HIGH A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme. | May 3, 2022 | 7.2 | 34 | NO | NO |
CVE-2020-23522MEDIUM Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. | Jan 19, 2021 | 6.8 | 32 | NO | YES |
CVE-2025-5206CRITICAL A vulnerability classified as critical was found in Pixelimity 1.0. Affected by this vulnerability is an unknown functionality of the file /install/index.php of the component Insta | May 26, 2025 | 9.8 | 25 | NO | NO |
CVE-2021-42866MEDIUM A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php | Mar 31, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-28589MEDIUM A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or HTML via the Title field in admin/pages.php?action=add_new | May 3, 2022 | 4.8 | 18 | NO | NO |
CVE-2021-29056MEDIUM Cross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php. | Aug 17, 2021 | 4.8 | 18 | NO | NO |
CVE-2018-19919MEDIUM Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload attribute of an SVG element. | Dec 6, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelimity.
Media articles that mention a CVE ID that affects a product developed by Pixelimity — matched by CVE ID, not by vendor name.