Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Relevanssi

First CVE: Jan 2, 2015Active for: 12 yearsTotal CVEs: 11
36.8
VTI Score
Medium

Relevanssi is a search-optimization plugin for WordPress that operates within a large ecosystem of content-management deployments, making its vulnerabilities relevant across many instances despite a narrow product focus. The plugin's disclosures center on application-layer weaknesses including cross-site scripting, authorization bypass, and sensitive-information exposure—characteristic of web-facing search and filtering logic—and frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Relevanssi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 2015
11 years ago
Most Recent CVE
Oct 8, 2024
654 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1380MEDIUM
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function i
Mar 13, 20245.360NOYES
CVE-2016-10949HIGH
The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
Sep 13, 20198.828NONO
CVE-2018-9034MEDIUM
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the ta
Apr 4, 20185.427NOYES
CVE-2024-3214CRITICAL
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attack
Apr 9, 20249.824NONO
CVE-2024-3213HIGH
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() functio
Apr 9, 20248.223NONO
CVE-2024-7630HIGH
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevan
Aug 16, 20247.521NONO
CVE-2017-1000225MEDIUM
Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can
Nov 17, 20176.120NONO
CVE-2023-7199MEDIUM
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted reque
Jan 29, 20245.318NONO
CVE-2017-1000038MEDIUM
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
Jul 17, 20176.118NONO
CVE-2024-9021MEDIUM
In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embeddi
Oct 8, 20245.416NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
27%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (90.9%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High0 (0.0%)
Unknown1 (9.1%)
User Interaction
None5 (45.5%)
Unknown1 (9.1%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None8 (72.7%)
Unknown1 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Relevanssi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Relevanssi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Relevanssi's Products

View all 3 CNAs →

Top CWEs