Realbigplugins develops web-based WordPress plugins, primarily the Client Dash product for managing client-facing dashboards, which expose a modest surface to input-handling vulnerabilities. The recurrent signal centers on cross-site scripting weaknesses in page-generation logic, a characteristic risk in web applications handling user-supplied content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Realbigplugins over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17071MEDIUM The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS. | Oct 10, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-33652MEDIUM Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1. | Apr 29, 2024 | 5.3 | 17 | NO | NO |
CVE-2023-49165MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: | Dec 15, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Realbigplugins.
Media articles that mention a CVE ID that affects a product developed by Realbigplugins — matched by CVE ID, not by vendor name.