Post Indexer Project maintains a specialized indexing and search utility with a focused vulnerability profile centered on input-handling weaknesses in its core product. The observed weakness classes, including improper input validation and SQL injection, reflect the data-parsing and query-construction attack surface inherent to an indexing system. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Post Indexer Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10948HIGH The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function. | Sep 13, 2019 | 8.1 | 26 | NO | NO |
CVE-2016-10947HIGH The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. | Sep 13, 2019 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Post Indexer Project.
Media articles that mention a CVE ID that affects a product developed by Post Indexer Project — matched by CVE ID, not by vendor name.