Plainware maintains a narrow product portfolio centered on web-based tools such as ShiftController and LocatorAid, which despite modest volume occupy a more prominent niche in their domain than the overall vulnerability count might suggest. The recurring vulnerability patterns reflect application-layer design, with exposures concentrating in cross-site scripting and cross-site request forgery—weakness classes typical of web interfaces where input handling and session validation are critical. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Plainware over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25709HIGH Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions. | Mar 15, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-29425HIGH Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions. | Nov 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-4476MEDIUM The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cros | Sep 25, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-9435MEDIUM The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to | Oct 4, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-2031MEDIUM The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insuffi | Jun 9, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-1978MEDIUM The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the query string in versions up to, and including, 4.9.25 due | Jun 9, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-29424MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions. | Jun 26, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Plainware.
Media articles that mention a CVE ID that affects a product developed by Plainware — matched by CVE ID, not by vendor name.