Raygun is an application performance monitoring and error-tracking platform, with its observed vulnerability surface centered on the Raygun4WP WordPress plugin. The recurring signal is cross-site scripting exposure in web-facing plugin functionality, a pattern characteristic of third-party WordPress extensions handling user input and content rendering. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raygun over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9288MEDIUM The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter). | May 29, 2017 | 6.1 | 32 | NO | YES |
CVE-2017-18531MEDIUM The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288. | Aug 20, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raygun.
Media articles that mention a CVE ID that affects a product developed by Raygun — matched by CVE ID, not by vendor name.