Reneade operates web-based social media management tools such as PostLists and TwitterPosts, where its disclosed vulnerabilities center on client-side input handling and cross-site request forgery issues typical of web applications with user-generated content and third-party integrations. The recurring weakness classes—cross-site scripting and CSRF—reflect the exposure inherent to browser-facing applications that handle untrusted input and cross-origin requests. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reneade over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-10815MEDIUM The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Si | Jan 9, 2025 | 4.2 | 15 | NO | NO |
The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via | May 15, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reneade.
Media articles that mention a CVE ID that affects a product developed by Reneade — matched by CVE ID, not by vendor name.