Popozure develops the LinkCard web-facing product, which exhibits a concentrated vulnerability pattern centered on web-application input handling and request validation issues such as cross-site scripting, cross-site request forgery, and server-side request forgery. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Popozure over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25012MEDIUM The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them back in admin dashboard pages, leading to Reflected Cross-S | Mar 28, 2022 | 6.1 | 22 | NO | NO |
CVE-2024-0672HIGH The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou | Mar 28, 2024 | 7.1 | 20 | NO | NO |
CVE-2023-47790MEDIUM Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in Poporon Pz-LinkCard plugin <= 2.4.8 versions. | Nov 23, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-0673MEDIUM The Pz-LinkCard WordPress plugin through 2.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripti | Mar 28, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-0677MEDIUM The Pz-LinkCard WordPress plugin through 2.5.1 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contri | Mar 28, 2024 | 5.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Popozure.
Media articles that mention a CVE ID that affects a product developed by Popozure — matched by CVE ID, not by vendor name.