Richweb develops a modestly scoped portfolio of web-based interface and content components, including tools for galleries, sliders, timelines, and embedded media, where vulnerabilities cluster around cross-site scripting arising from improper input neutralization in page generation. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Richweb over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24831HIGH All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data i | Jan 3, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-1327MEDIUM The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow high-privileged users such as admin to perform Cross-Site S | Jun 27, 2022 | 4.8 | 16 | NO | NO |
CVE-2022-1322MEDIUM The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site | Aug 22, 2022 | 4.8 | 15 | NO | NO |
CVE-2022-1324MEDIUM The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting | Aug 1, 2022 | 4.8 | 15 | NO | NO |
CVE-2022-1541MEDIUM The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow high-privileged users to perform Cross-Site Scripting attac | Jun 8, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Richweb.
Media articles that mention a CVE ID that affects a product developed by Richweb — matched by CVE ID, not by vendor name.