Rich Web maintains a narrowly scoped portfolio of web-interface components and plugins, including products such as Coming Soon, Event Timeline, Image Gallery, and Tab functionality. The observed vulnerability surface spans general application-layer concerns without a clearly concentrated weakness pattern; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rich Web over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24831HIGH All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data i | Jan 3, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-1327MEDIUM The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site S | Jun 27, 2022 | 4.8 | 16 | NO | NO |
CVE-2022-1322MEDIUM The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site | Aug 22, 2022 | 4.8 | 15 | NO | NO |
CVE-2022-1324MEDIUM The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting | Aug 1, 2022 | 4.8 | 15 | NO | NO |
CVE-2022-1541MEDIUM The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attac | Jun 8, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rich Web.
Media articles that mention a CVE ID that affects a product developed by Rich Web — matched by CVE ID, not by vendor name.