Riverside's disclosures center on HTTP headers handling within web infrastructure, with the recurring vulnerability pattern centered on web-application input-handling weaknesses including cross-site scripting, server-side request forgery, and related validation gaps. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Riverside over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1208HIGH This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a Remote Code Execution vulnerability. | Jul 10, 2023 | 7.2 | 20 | NO | NO |
CVE-2023-1207HIGH This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability. | May 15, 2023 | 7.2 | 20 | NO | NO |
CVE-2023-37978MEDIUM Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/a through 1.18.11. | Nov 13, 2023 | 4.9 | 16 | NO | NO |
CVE-2023-37874MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dimitar Ivanov HTTP Headers plugin <= 1.18.11 versions. | Aug 5, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Riverside.
Media articles that mention a CVE ID that affects a product developed by Riverside — matched by CVE ID, not by vendor name.