Radykal's vulnerability footprint centers on its Fancy Product Designer, a web-based design tool that is positioned prominently in its niche. Vulnerabilities affecting this product skew toward serious outcomes and frequently acquire public exploit code, with recurring exposure in web application-layer weakness classes including cross-site scripting, SQL injection, improper authorization, unsafe file uploads, and cross-site request forgery that are characteristic of interactive design platforms. Defenders should prioritize patching this vendor's advisories and audit access controls on instances exposed to untrusted users; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radykal over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24370CRITICAL The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution. | Jun 21, 2021 | 9.8 | 69 | NO | YES |
CVE-2024-51818CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy | Jan 21, 2025 | 9.3 | 34 | NO | NO |
CVE-2021-4096HIGH The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious | Apr 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-51919CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through < | Jan 21, 2025 | 9.0 | 25 | NO | NO |
CVE-2021-4334HIGH The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in v | Oct 20, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-12570HIGH The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient in | Dec 12, 2025 | 7.2 | 24 | NO | NO |
CVE-2021-4335MEDIUM The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized access to data and modification of plugin settings due to a missing capability check on multiple AJAX | Oct 20, 2023 | 6.3 | 22 | NO | NO |
CVE-2025-13231MEDIUM The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use | Dec 16, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-15526MEDIUM The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF | Jan 16, 2026 | 5.3 | 20 | NO | NO |
CVE-2025-13439MEDIUM The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insuffi | Dec 16, 2025 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radykal.
Media articles that mention a CVE ID that affects a product developed by Radykal — matched by CVE ID, not by vendor name.