Resmush.It is an image-optimization and compression service whose vulnerability surface centers on its web-facing optimizer product and web-layer security concerns including cross-site request forgery, cross-site scripting, and missing authorization controls. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Resmush.It over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2449MEDIUM The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to tr | Nov 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-2450MEDIUM The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as su | Nov 14, 2022 | 4.3 | 19 | NO | NO |
CVE-2022-2448MEDIUM The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Sc | Oct 10, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Resmush.It.
Media articles that mention a CVE ID that affects a product developed by Resmush.It — matched by CVE ID, not by vendor name.