Prisna's vulnerability profile centers on the Google Website Translator product, a web-localization tool with a narrow but notable deployment footprint. The recurring weakness classes—cross-site scripting and deserialization of untrusted data—reflect the product's role in parsing and rendering user-supplied content across web pages, exposing it to both injection and unsafe object-handling risks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prisna over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8514HIGH The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted | Sep 25, 2024 | 7.2 | 22 | NO | NO |
CVE-2024-12680MEDIUM The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | May 15, 2025 | 4.8 | 15 | NO | NO |
CVE-2024-12679MEDIUM The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | May 15, 2025 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prisna.
Media articles that mention a CVE ID that affects a product developed by Prisna — matched by CVE ID, not by vendor name.