Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rednao

First CVE: Mar 12, 2019Active for: 7 yearsTotal CVEs: 21
14.7
VTI Score
Low

Rednao develops a focused portfolio of WordPress plugins and donation-management tools, including Smart Forms, Smart Donations, and WooCommerce PDF Invoice Builder, which serve small-to-medium business and nonprofit segments. The vendor's vulnerability profile concentrates on web-application input-handling and authorization issues endemic to plugin-based WordPress extensions, with recurring weakness classes including cross-site scripting, cross-site request forgery, SQL injection, and missing or improper authorization controls. These classes reflect the challenges of securing dynamically generated content and form processing in plugin architectures where privilege enforcement and input sanitization are critical. Defenders deploying Rednao plugins should prioritize timely updates and review access controls around administrative and donation-processing functions; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rednao over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2019
7 years ago
Most Recent CVE
Dec 13, 2024
588 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38475HIGH
Missing Authorization vulnerability in RedNao Donations Made Easy – Smart Donations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Donat
Dec 13, 20248.828NONO
CVE-2023-40207CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue a
Nov 6, 20239.828NONO
CVE-2019-5924HIGH
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted pag
Mar 12, 20198.827NONO
CVE-2023-49856HIGH
Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: fr
Dec 9, 20248.824NONO
CVE-2023-47551HIGH
Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.
Nov 18, 20238.824NONO
CVE-2023-3677HIGH
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escapi
Aug 31, 20238.824NONO
CVE-2023-51486HIGH
Cross-Site Request Forgery (CSRF) vulnerability in RedNao WooCommerce PDF Invoice Builder.This issue affects WooCommerce PDF Invoice Builder: from n/a through 1.2.101.
Mar 16, 20248.823NONO
CVE-2022-0163MEDIUM
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber,
Mar 7, 20226.523NONO
CVE-2024-1307MEDIUM
The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perf
Apr 15, 20246.522NONO
CVE-2023-7203MEDIUM
The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perfor
Feb 27, 20246.120NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
67%
29%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (38.1%)
Unknown0 (0.0%)
Required13 (61.9%)
Privileges Required
Low8 (38.1%)
High2 (9.5%)
None11 (52.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rednao.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rednao — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rednao's Products

View all 4 CNAs →

Top CWEs