Simple Link Directory
Vendor:
First CVE: Mar 20, 2020 · Active for 6 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Simple Link Directory over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2020
6 years ago
Most Recent CVE
Jul 2, 2026
22 days ago
CVE Severity & Scoring
Simple Link Directory13 CVEs
54%
31%
15%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None9 (69.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0760CRITICAL The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX actio | Mar 21, 2022 | 9.8 | 39 | NO | YES |
CVE-2026-57682HIGH Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | Jul 2, 2026 | 7.1 | 31 | NO | NO |
CVE-2025-49901CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects | Oct 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-7209MEDIUM The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2 | May 2, 2026 | 6.4 | 26 | NO | NO |
CVE-2026-53742MEDIUM Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can cra | Jun 10, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-53741MEDIUM Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact | Jun 10, 2026 | 5.4 | 25 | NO | NO |
CVE-2025-67465HIGH Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross Site Request Forgery.This issue affects Simple Link Directo | Dec 9, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-48297HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected X | Aug 20, 2025 | 7.1 | 23 | NO | NO |
CVE-2025-32297HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injecti | Jul 4, 2025 | 8.5 | 23 | NO | NO |
CVE-2019-13463MEDIUM An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, | Mar 20, 2020 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Simple Link Directory
Top CWEs
Versions
No cataloged versions.